62 terms outbound teams run into, from SPF and DMARC alignment to spam traps, gateways and warmup, each defined in a sentence or three, with a link to the deeper guide where we have one.
The records that prove a message really comes from your domain, and the DNS around them.
Sender Policy Framework. A TXT record on a domain that lists the servers allowed to send mail for it, checked against the envelope sender (Return-Path) of each message. A record ending in -all tells receivers to fail mail from any server not listed. A domain can have only one SPF record, and it must resolve in 10 DNS lookups or fewer.
More: SPF record generator
DomainKeys Identified Mail. The sending server signs each message with a private key, and the receiver checks the signature against a public key published in DNS at selector._domainkey.yourdomain.com. A valid signature shows the message was not altered in transit and ties it to the signing domain in the d= tag.
More: DKIM record generator
Domain-based Message Authentication, Reporting and Conformance. A TXT record at _dmarc.yourdomain.com that tells receivers what to do with mail that fails aligned SPF and DKIM: p=none (deliver and report), p=quarantine (treat as spam) or p=reject (refuse), plus an address for aggregate reports (rua).
More: Why Winnr uses DMARC p=reject · DMARC record generator
DMARC passes only when SPF or DKIM passes for a domain that matches the visible From domain. Relaxed alignment, the default, accepts a match on the organizational domain (mail.example.com aligns with example.com); strict alignment needs an exact match. Passing SPF for some other domain does not count.
The address in the SMTP MAIL FROM command, where bounces are sent. Recipients rarely see it. SPF is checked against this domain, not the From address, which is why alignment exists.
Mail exchanger. The DNS record that tells other servers where to deliver mail for a domain. A sending domain still needs a working MX so replies and bounces arrive; on Winnr domains it is 10 inbound.yourdomain.com.
More: DNS lookup tool
Maps a hostname to an IPv4 address. On cold email domains, A records point hostnames at the inbound mail server or at the web server that handles a redirect.
Maps an IP address back to a hostname, the reverse of an A record. Receiving servers expect a sending IP to have one, and expect that hostname to resolve back to the same IP (forward-confirmed reverse DNS). The IP's owner sets it, so on managed infrastructure it is the provider's job.
The servers that answer DNS queries for a domain, set at the registrar. Pointing a domain's nameservers at a provider hands it the whole zone, which is how Winnr manages every record on domains connected that way.
TTL (time to live) is how many seconds resolvers may cache a DNS answer. A change is seen everywhere only once old cached answers expire, which is why record and nameserver changes can take anywhere from minutes to 48 hours to apply worldwide.
Brand Indicators for Message Identification. A DNS record pointing to your logo so supporting inboxes can show it next to authenticated mail. It requires DMARC at quarantine or reject, and Gmail also requires a Verified Mark Certificate or Common Mark Certificate. It does not decide inbox placement and is rarely worth it on rotating cold email domains.
More: BIMI for cold email
A subdomain of your own, usually a CNAME, that your sequencer uses for open pixels and tracked links instead of its shared tracking domain, so your links are not tied to other senders' reputation.
A 301 redirect that sends visitors of a sending domain to your main website. Prospects sometimes check the sender's domain, and a blank or parked page looks fake.
Whether mail arrives, where it lands, and what decides it.
The share of sent messages the receiving server accepted rather than bounced. Accepted mail can still go to spam, so a high delivery rate says nothing about inbox placement. People often say deliverability when they mean either one.
The share of delivered messages that reach the inbox rather than spam or a promotions tab. Mailbox providers do not report it to senders, so it is estimated with seed tests.
Sending a message to a set of test mailboxes at Gmail, Outlook, Yahoo and business gateways, then checking which folder each copy reached. Run one to the providers your prospects use before scaling a new set of mailboxes.
The share of delivered messages recipients mark as spam. Gmail asks bulk senders to keep the rate shown in Postmaster Tools below 0.1% and never reach 0.3%. Cold email should aim far lower.
A program in which a mailbox provider reports spam complaints back to the sender so it can stop mailing those people. Yahoo and Microsoft run per-message loops; Gmail's version reports aggregate data only.
A permanent failure, usually because the address does not exist, returned as a 5xx code such as 550 5.1.1. Remove hard-bounced addresses at once; a rising hard-bounce rate means the list needs verifying.
More: Bounces and rejections
A temporary failure, such as a full mailbox, a server problem or rate limiting, returned as a 4xx code. The sending server retries for a while before giving up.
The three-digit codes a receiving server returns: 2xx accepted, 4xx temporary failure, 5xx permanent failure. Enhanced codes such as 5.7.1 add detail, and the text after the code usually says why a message was refused.
A receiving server answering with a 4xx code to slow a sender down, often because the volume from that IP or domain is new or unusual. Persistent deferrals at one provider are an early reputation warning.
The trust a mailbox provider assigns a sender, built from complaints, engagement, bounces, spam-trap hits and consistency over time. Providers track it for the sending domain and for the sending IP.
Reputation tied to the domain in the From address and the DKIM signature. It follows the domain whichever server sends its mail, which is why cold email runs on separate domains.
Reputation tied to the sending server's IP address. On a shared IP it is pooled across every sender using it; on a dedicated IP it belongs to one sender.
A list of IP addresses or domains with a record of sending spam, published as DNS lookups that receiving filters query. Some lists, such as Spamhaus ZEN, list IPs; others, such as Spamhaus DBL and SURBL, list domains.
A blocklist of domains that appear in spam, including in links and signatures, not only in the From address. Filters look up every domain in a message, so a listed domain hurts any email that mentions it, whichever server sends it.
An address that exists to catch senders who mail people who never engaged: pristine traps never belonged to a person, recycled traps are abandoned addresses reactivated after a dormant period, and typo traps sit on misspelled domains. Hits point to a scraped or stale list.
A filtering service in front of a company's mailboxes, such as Proofpoint, Mimecast or Barracuda. It scans inbound mail before Microsoft 365 or Google Workspace receives it, so B2B cold email has to pass the gateway's filters as well as the mailbox provider's.
Gmail's free dashboard showing a domain's spam rate, authentication results and delivery errors for mail sent to Gmail users. Data appears only once a domain sends a meaningful daily volume to Gmail. Microsoft's SNDS gives similar data per IP for Outlook.com.
Rules Gmail and Yahoo apply to senders of more than 5,000 messages a day to their users, enforced since February 2024: SPF and DKIM, a DMARC policy, alignment, one-click unsubscribe on marketing mail and a low spam rate. Outlook.com added similar rules for high-volume senders on May 5, 2025.
The List-Unsubscribe and List-Unsubscribe-Post headers (RFC 8058), which let a recipient unsubscribe from the inbox without visiting a page. Gmail and Yahoo require them on bulk marketing mail. Cold email should always give recipients a clear way to opt out.
Words and phrases associated with spam, such as free, guarantee and act now. Modern filters weigh content far less than reputation and authentication, but piling them up still hurts.
More: Spam word checker
What you send from, and how it is hosted.
A domain used only for outbound, separate from your company's primary domain, so reputation damage from cold email cannot reach the domain your business runs on.
More: Cold email domains
A sending domain built from your brand, such as getacme.com or acme-hq.co. A set of them forms one pattern a filter can match, and in the test we published, 501,000 emails showed no reply-rate difference between branded and generic domains.
Top-level domain: the extension at the end of a domain, such as .com or .io. Cheap, mass-registered extensions such as .xyz and .info are filtered more harshly; .com, .co, .net and .org are safe defaults.
More: Best TLDs for cold email
A domain registered well before it is used to send. Age on its own is a weak signal; age combined with a clean sending history is what carries weight.
More: Aged vs new domains
A domain whose reputation has collapsed through complaints, spam-trap hits or a blocklisting, so its mail is filtered or refused almost everywhere. Replacing it is usually faster than repairing it.
More: Recover a burned domain
Sending from subdomains such as hello.example.io, each with its own SPF, DKIM, DMARC and MX. It means fewer registrations, but a problem on the main domain affects all of its subdomains.
More: The Subdomain Strategy
How many sending mailboxes share one domain. Fewer limits the damage when a domain runs into trouble; Winnr creates 5 per domain by default and allows up to 10.
A sending account with an SMTP login for sending and an IMAP login for reading replies, which is what a sequencer needs. Winnr mailboxes use SMTP on port 465 and IMAP on port 993, both over SSL.
More: SMTP for cold email
Simple Mail Transfer Protocol, used to send mail. Apps submit mail on port 465 (implicit TLS) or 587 (STARTTLS); port 25 is for server-to-server delivery.
Internet Message Access Protocol, used to read a mailbox from a remote client. Sequencers use it to spot replies and stop a sequence; port 993 is IMAP over SSL.
SMTP AUTH is logging in to an SMTP server before sending. Basic Auth does it with a username and password. Microsoft disables Basic Auth for SMTP AUTH by default in existing Exchange Online tenants at the end of December 2026, leaving OAuth.
An authorization standard in which an app receives a time-limited access token instead of your password. Google and Microsoft accounts connect to sequencers this way; tokens have to be refreshed and can be revoked.
A separate, generated password for an app that cannot use OAuth. In Microsoft 365 it is a form of Basic Auth and stops working when Basic Auth is disabled.
A sending IP used by one sender only, so its reputation is entirely that sender's. It pays off at high, steady volume and works against you when volume is too low or irregular to build a reputation. On Winnr it is optional, at $20 per IP per month on Enterprise.
More: Dedicated IPs
Sending from the same provider your prospect uses: Google mailboxes to Google-hosted recipients, Microsoft mailboxes to Microsoft-hosted ones. Sellers of Google and Microsoft inboxes recommend it; how much it helps varies, so test it with seeds.
A Microsoft 365 mailbox provisioned in bulk in a tenant a seller sets up, and sold cheaply for cold email, often with many mailboxes on one domain. Also sold as Entra or Outlook inboxes.
How campaigns run across many mailboxes.
Software that runs cold email campaigns across many connected mailboxes: lead lists, multi-step sequences, scheduling, rotation and reply detection. Instantly, Smartlead and EmailBison are examples. Winnr supplies the mailboxes they send through.
A sequencer spreading a campaign's sends across many mailboxes so each stays under its daily limit. More volume comes from more mailboxes, not more sends per mailbox.
The most emails a mailbox sends in a day. On Winnr, plan for about 50 per mailbox in total including warming, with 10 to 20 of them cold email.
Raising a new mailbox's daily volume gradually over its first weeks instead of starting at full volume.
Building a new mailbox's sending history before cold email by exchanging realistic emails, with replies, with other mailboxes. Plan for at least two weeks, and four on a brand-new domain.
The pool of mailboxes that warming emails are exchanged with. Its mix of providers matters: a network with few Outlook.com addresses does little for reputation at Microsoft, so check placement there with a seed test.
A mailbox on an aged domain that has already been warmed and is sold ready to send. On Winnr's marketplace they cost $3 per address per month with no minimum term.
More: Pre-warmed domains
One view of the replies to every sending mailbox. Winnr's is the universal mailbox; most sequencers have their own.
More: Universal mailbox
Syntax such as {Hi|Hello|Hey} that a sequencer expands into a different variant for each recipient, so messages are not all identical.
More: Spintax for cold email
Checking a list before sending to remove addresses that would bounce. Catch-all and role addresses (info@, sales@) are flagged as risky rather than confirmed.
A domain whose mail server accepts mail for any address, so verification cannot confirm that a particular mailbox exists. Mail to unverified catch-all addresses carries bounce risk.
A tiny image in the message that reports when it loads. Privacy features that preload images make open counts unreliable, and the tracking link adds another domain to the message, so many cold emailers turn it off.
Definitions describe common industry usage as of October 2026. Provider rules change; where a number or date matters, the linked guide gives the source. Spotted something wrong? Our editorial standards explain how to report it.
SPF, DKIM and DMARC on every domain, built-in warming, and plans from $69/month for 50 mailboxes.
Get started