The Complete Cold Email Infrastructure Audit: 25 Checks Every Team Should Run in 2026
Most cold email deliverability problems have the same root cause: infrastructure that was set up once, improperly, and never reviewed. This 25-point checklist covers every layer — domains, authentication, inboxes, warmup, list quality, and compliance — with specific tools and clear pass/fail criteria.
Why an Audit Is Your Starting Point
Most cold email deliverability problems have the same root cause: infrastructure that was set up once, improperly or incompletely, and never reviewed. Teams send campaign after campaign from a domain that has been quietly accumulating reputation damage for months, wondering why reply rates keep declining.
A cold email infrastructure audit takes less than two hours. It catches the problems that cause 70% of deliverability failures before they cascade. This 25-point checklist covers every layer of cold email infrastructure — domains, authentication, inboxes, warmup, list quality, compliance, and monitoring — with specific tools for each check and clear pass/fail criteria.
Run this audit on every domain in your sending infrastructure, not just your newest ones. Old domains accumulate configuration drift. Older setups often predate the 2024-2025 mandatory authentication requirements and may never have been properly updated.
Section 1: Domain Setup (Checks 1–5)
| # | Check | Tool | Pass Criteria |
|---|---|---|---|
| 1 | secondary domain in use (not primary company domain) | Visual check | Sending domain ≠ primary company domain |
| 2 | Domain redirect to main company website | Browser check | 301 redirect to company site; no parked page |
| 3 | Domain age (older domains have better trust) | Whois lookup | 90+ days old preferred for cold campaigns |
| 4 | No prior blacklist or spam history | MXToolbox / Talos | Clean history; not previously used for spam |
| 5 | Domain TLD is .com, .co, or .io | Visual check | Avoid .biz, .info, .online, .xyz for cold email |
Section 2: Authentication (Checks 6–11)
| # | Check | Tool | Pass Criteria |
|---|---|---|---|
| 6 | SPF record exists | MXToolbox SPF Lookup | TXT record present; no PermError; ~all or -all |
| 7 | Only one SPF record per domain | MXToolbox SPF Lookup | Exactly 1 SPF TXT record; 2 = PermError |
| 8 | SPF under 10 DNS lookups | SPF flattening tool | Count all include: statements; must be under 10 |
| 9 | DKIM configured (2048-bit key) | MXToolbox DKIM Checker | Valid key; 2048-bit recommended; not 1024-bit |
| 10 | DMARC record exists (p=none minimum) | MXToolbox DMARC Lookup | _dmarc.domain.com TXT record present |
| 11 | DMARC alignment (From domain matches SPF/DKIM domain) | Mail-tester.com | SPF/DKIM domain = visible From domain |
Section 3: Inbox Configuration (Checks 12–16)
| # | Check | Tool | Pass Criteria |
|---|---|---|---|
| 12 | MX records configured | MXToolbox MX Lookup | Valid MX records pointing to email hosting provider |
| 13 | Custom tracking domain (not shared platform domain) | Sending platform settings | Subdomain CNAME pointing to platform tracking server |
| 14 | Inbox sending volume configured under 50/day | Sequencer settings | Hard daily send cap set per inbox |
| 15 | Inbox forwarding configured | Send test email; verify receipt | Replies reach your main inbox reliably |
| 16 | Inbox display name is a real human name | Settings check in email hosting | Not "Sales Team" or "Outreach" — use first/last name |
Section 4: Warmup and Reputation (Checks 17–20)
| # | Check | Tool | Pass Criteria |
|---|---|---|---|
| 17 | Inbox warmup completed (new inbox) | Warmup platform dashboard | Minimum 2–4 weeks warmup completed before cold sends |
| 18 | Warmup running continuously (not paused) | Warmup platform dashboard | Active warmup alongside campaigns; not turned off |
| 19 | domain reputation not Low or Bad | Google Postmaster Tools | High or Medium rating in Postmaster |
| 20 | Spam rate under 0.1% | Google Postmaster Tools | Spam rate graph consistently below 0.1% |
Section 5: List Quality (Checks 21–23)
| # | Check | Tool | Pass Criteria |
|---|---|---|---|
| 21 | Email list verified before campaign | ZeroBounce, NeverBounce, Hunter | All addresses verified; catch-all flagged as risky |
| 22 | Bounce rate under 2% in recent campaigns | Sequencer analytics | Hard bounces under 2%; remove all immediately |
| 23 | Suppression list maintained | Sequencer suppression settings | All opt-outs and hard bounces in suppression list |
Section 6: Compliance and Monitoring (Checks 24–25)
| # | Check | Tool | Pass Criteria |
|---|---|---|---|
| 24 | CAN-SPAM/GDPR compliance in templates | Review each template | Physical address present; opt-out mechanism included; non-deceptive subject lines |
| 25 | Blacklist monitoring active | MXToolbox weekly; automated alerts ideally | Domain and IP not on any major blacklist; active alert if listed |
How to Use This Audit
Run this checklist before launching any new campaign, before onboarding a new client (for agencies), and as a quarterly maintenance review for active sending infrastructure. Any failed check is a problem to fix before sending, not after.
For teams managing multiple domains, run the full audit on every domain independently. A problem on one domain doesn't necessarily mean a problem on others — but untested domains are assumptions, not guarantees.
If you complete this audit and find more than three failures, pause all campaigns until the issues are resolved. Sending from an infrastructure with multiple problems compounds the damage with every send.
Overall Scoring
| Score | Status | Action |
|---|---|---|
| 23–25 checks pass | Healthy infrastructure | Continue sending; maintain monthly monitoring |
| 20–22 checks pass | Minor issues | Fix failing checks before next campaign; no pause needed |
| 15–19 checks pass | Significant gaps | Fix authentication and warmup issues before sending |
| Under 15 checks pass | Critical problems | Pause campaigns immediately; don't send until resolved |
References
- Puzzle Inbox. Cold Email Domain Setup: The Complete DNS Configuration Guide (March 2026)
- Mailpool. Sender Reputation Recovery: The 90-Day Rehabilitation Plan (April 2026)
- MXToolbox. Email Health Checks and DNS Tools
- Google. Postmaster Tools — Domain Reputation Dashboard
- Topo.io. Cold Email Sending Limits: The 2025 Playbook for Not Getting Blacklisted (April 2026)
- Mailshake. Cold Email Compliance: The Essential 2026 Guide (April 2026)
Mailflo.co runs this audit for every domain in your cold email infrastructure and fixes what's broken — so your team never discovers a deliverability problem by watching reply rates collapse mid-campaign.
Written by
The Mailflo Team
The Mailflo team helps B2B sales teams land in the inbox and book more meetings through bulletproof email deliverability and smart automation.
LinkedIn