How to set up cold email infrastructure
End-to-end cold email setup: secondary domains, 4 to 6 mailboxes each, automatic SPF, DKIM and DMARC, 14-day warming, list check, launch check. Real API calls and costs.
The short answer
Setting up cold email infrastructure means buying or connecting secondary domains, putting 4 to 6 mailboxes on each, confirming SPF, DKIM, DMARC and MX on public DNS, warming for 14 days, verifying the list and launching one campaign at low volume. On EmailPal, 6 domains with 5 mailboxes each is 30 inboxes and about 450 cold emails a day at the recommended 15 per inbox. That costs about $87 a month on Starter ($69 plan with 50 mailboxes included, plus $18 for warming) and $6 to $60 once for the domains.
Use secondary domains, never your main one. Buy them or connect ones you own, wait for DNS to verify (EmailPal writes SPF, DKIM at RSA-2048 and Ed25519, DMARC at p=reject and MX, then re-checks them on public resolvers), create 4 to 6 mailboxes per domain, and leave warming on for 14 days before the first cold email. Verify the list, run the launch check, start at about 5 emails per mailbox per day and step up to 15. If you cannot wait 14 days, pre-warmed inboxes skip the ramp at $3 per month each with a 90-day minimum. EmailPal does not provide leads and hosts SMTP and IMAP mailboxes, not Google or Microsoft seats.
How it works, step by step
Step 1
Choose secondary domains, not your main domain
Pick lookalike names such as getacme.com or tryacme.com that read like a real company, and avoid words such as outreach, blast or bulk. Plan 4 to 6 mailboxes per domain (about 5), so 30 mailboxes means 5 to 8 domains, and 6 domains with 5 mailboxes each is a comfortable shape. A burned sending domain should cost you a lookalike name, not your company’s transactional mail.
Step 2
Create an API key and check the account
Under API keys in the dashboard, create a key with write scope (write covers domains, mailboxes, warming and campaigns). GET /account returns your plan, mailbox and domain usage against the limits, and domain_balance_cents, which you need before buying domains. Everything below can also be done in the dashboard, and the dashboard paths are noted in each step.
GET /api/public/v1/accountbashcurl https://www.emailpal.io/api/public/v1/account \ -H "Authorization: Bearer $EMAILPAL_API_KEY"Step 3
Check names, then buy them or connect domains you own
Dashboard: Domains, then search and register. API: POST /domains/search prices names without reserving them, then POST /domains with mode purchase takes the whole batch off your prepaid domain balance, or nothing if the balance falls short. For a domain you already own, use mode connect: it is free, uses one domain slot, and takes dns_method nameservers (the default) or manual. Send an Idempotency-Key header so a retry after a timeout cannot buy twice.
POST /api/public/v1/domainsbashcurl -X POST https://www.emailpal.io/api/public/v1/domains \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Idempotency-Key: 6b0c2f8e-91d4-4a7b-8e35-2f1c9d7a40b3" \ -H "Content-Type: application/json" \ -d '{ "mode": "purchase", "domains": ["getnorthworks.com", "trynorthworks.com", "northworks-hq.com"], "years": 1, "tags": ["outbound"] }'Step 4
Wait for DNS, then check it yourself with dig
The response is 202 with a job_id per domain. Poll GET /jobs/{id} or GET /domains/{id} until the domain is ready; registration and DNS verification take minutes, and a connected domain stays in needs_dns until public DNS agrees. Then confirm the records from a public resolver, because that is what mailbox providers see. The DKIM selector names carry a date, so copy the exact names from GET /domains/{id}.
Verify records on a public resolverbash# SPF: one TXT record that starts v=spf1 and ends -all dig @8.8.8.8 +short TXT getnorthworks.com # DMARC: should contain p=reject dig @8.8.8.8 +short TXT _dmarc.getnorthworks.com # MX: replies are delivered here dig @8.8.8.8 +short MX getnorthworks.com # DKIM: use the selector names shown by GET /domains/{id} dig @8.8.8.8 +short TXT <rsa-selector>._domainkey.getnorthworks.com dig @8.8.8.8 +short TXT <ed-selector>._domainkey.getnorthworks.comStep 5
Create 4 to 6 mailboxes on each ready domain
Dashboard: Mailboxes, then new. API: POST /mailboxes takes a domain_id that is ready or active, plus count (up to 100 per call), personas or named local parts. Use a person-style pattern such as first.last. A mailbox can send as soon as it exists, but a new domain should not send cold email yet. The response lists the addresses and a job_id to poll.
POST /api/public/v1/mailboxesbashcurl -X POST https://www.emailpal.io/api/public/v1/mailboxes \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Idempotency-Key: c41e7d02-5a8b-4f36-9b17-0d3e8a2f6c59" \ -H "Content-Type: application/json" \ -d '{ "domain_id": "dom_91af22", "count": 5, "pattern": "first.last", "warming_profile": "standard" }'Step 6
Turn warming on and leave it on
Warming defaults to on when you create mailboxes through the API, at $0.60 per inbox per month. Use the standard profile for a brand-new domain (about 2 warming messages a day rising to about 20 over roughly 14 days) and accelerated only for an aged domain. If you created mailboxes with warming off, POST /warming switches it on for up to 500 mailboxes at once. Warming is withheld on an account with no active subscription.
POST /api/public/v1/warmingbashcurl -X POST https://www.emailpal.io/api/public/v1/warming \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Content-Type: application/json" \ -d '{"action": "enable", "mailbox_ids": ["mbx_2c81f0", "mbx_2c81f1", "mbx_2c81f2"]}'Step 7
Verify the list while the mailboxes warm
Use the 14 days to clean the list. POST /lists/verify takes the raw file contents and checks every address, and the dashboard does the same on upload. Verification costs one credit per address against the plan’s daily allowance (500 instant checks a day on Starter). Invalid addresses never send in EmailPal’s sequencer, and bounces in the first week are the quickest way to undo a ramp.
POST /api/public/v1/lists/verifybashcurl -X POST https://www.emailpal.io/api/public/v1/lists/verify \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Content-Type: application/json" \ -d '{"filename": "q4-prospects.csv", "content": "email\npriya@acme.example\nsam@example.org"}'Step 8
Build the first campaign and run the launch check
Dashboard: Engage, then New campaign; the Ready to launch dialog lists blockers and warnings. API: POST /campaigns creates a draft with your steps and mailbox_ids, POST /campaigns/{id}/leads adds leads (anyone blocklisted, unsubscribed, bounced or failed by verification is skipped), and GET /campaigns/{id}/preflight returns the same checklist as the dashboard. POST /campaigns/{id}/launch runs it again, returns 409 launch_blocked if anything blocks, and has no flag to skip it.
GET /api/public/v1/campaigns/{id}/preflightbashcurl https://www.emailpal.io/api/public/v1/campaigns/5d3c0b1e-6a52-4f0e-9d53-1d0b9f2a7c11/preflight \ -H "Authorization: Bearer $EMAILPAL_API_KEY" # can_launch: true -> launch curl -X POST https://www.emailpal.io/api/public/v1/campaigns/5d3c0b1e-6a52-4f0e-9d53-1d0b9f2a7c11/launch \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Idempotency-Key: 0e9a5d3c-7b21-4c84-a6f0-3d5b8e1c7a92"Step 9
Ramp volume with a campaign daily limit
Wait until mailboxes show campaign_ready (14 days of warming), then start low. With 30 mailboxes, a campaign daily_limit of 150 is about 5 per mailbox per day. Raise it to 300 in the second week and 450 from the third or fourth week if bounces stay near zero and replies arrive. This schedule is conservative guidance, not an EmailPal rule. Keep warming on while you send; warming messages do not count toward the cold cap.
PATCH /api/public/v1/campaigns/{id}bashcurl -X PATCH https://www.emailpal.io/api/public/v1/campaigns/5d3c0b1e-6a52-4f0e-9d53-1d0b9f2a7c11 \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Content-Type: application/json" \ -d '{"daily_limit": 150}'Step 10
Monitor placement, bounces and pauses
GET /warming shows ramp progress, campaign_ready counts and the measured inbox rate. GET /mailboxes/{id} adds health_score and a sending_pause block. GET /campaigns/{id}/analytics shows bounces per step. Subscribe to webhooks such as domain.failed, mailbox.failed and campaign.paused instead of polling, since polling spends the 1,000-requests-an-hour budget. When a campaign or mailbox pauses, fix the cause before resuming.
GET /api/public/v1/warmingbashcurl "https://www.emailpal.io/api/public/v1/warming?days=7" \ -H "Authorization: Bearer $EMAILPAL_API_KEY"
01
How many domains and mailboxes you need
Volume comes from the number of mailboxes, not from raising the per-mailbox figure. EmailPal recommends 15 cold emails a day per inbox, and the mail server enforces a hard ceiling of 100 a day on any address. That ceiling is a limit, not a target: past about 15 a day, placement falls away enough that extra messages cost more in replies than they add in volume.
Divide the daily volume you want by 15 to get mailboxes, then divide by 4 to 6 mailboxes per domain to get domains. At 450 a day that is 30 mailboxes and 5 to 8 domains. Starter’s 50 mailboxes at 15 a day is 750 sends, spread over roughly 9 to 13 domains. For the larger sizes, see the page on scaling to 1,000 a day.
The 4 to 6 range is what the mailbox form suggests, and it warns once a domain passes about 10. It is deliverability advice, not a product limit on domains you own. Providers correlate mailboxes that share a domain, so one address that earns complaints affects its siblings. Twenty mailboxes on a two-week-old domain is how a whole name gets filtered at once.
02
What DNS EmailPal writes, and how to verify it
On domains EmailPal registers, and on domains you connect once nameservers are delegated or you add the records manually, the platform publishes an MX record so replies can arrive, SPF with a hard fail (-all), two DKIM keys (RSA-2048 and Ed25519) and DMARC at p=reject. It then re-checks them against public resolvers rather than its own view of DNS, so a verified record means the internet sees it.
You rarely edit these, but you should look once. Use a public resolver in dig, as in the DNS step above. SPF should be a single TXT record on the domain, because a second record that starts v=spf1 fails SPF. DMARC should show p=reject. DKIM selector names are dated, so take the exact names from the records list on GET /domains/{id}, which shows expected and observed values and a status for each record.
For a connected domain, the default dns_method of nameservers delegates the whole zone to EmailPal, which then keeps the records correct. Manual leaves DNS in your hands, including after a DKIM rotation, so watch for a record whose status turns mismatch. Do not put cold email on a domain whose MX still receives your company’s real mail: inbound follows MX.
03
Cost worked example: 6 domains, 5 mailboxes each
Domains are a one-time registrar price paid from a prepaid balance, from $1 to $10 each depending on the extension (.xyz $1, .info $2, .biz $5, .com $10 on the pricing page, and the price_cents in a search response is the exact figure). Six domains are therefore $6 to $60 once. The domains stay yours if you leave.
Thirty mailboxes sit inside Starter’s 50 included mailboxes, so there is no $1 overage. The plan is $69 a month, and warming on all 30 is 30 x $0.60 = $18 a month, for $87 a month. Thirty mailboxes at 15 a day is 450 cold emails a day. The first month, with six .com domains, is about $147 including the domains. Six domains use 6 of Starter’s 50 domain slots.
Pre-warmed inboxes change the shape, not the plan fee. Thirty leases at $3 are $90 a month with a 90-day minimum ($270), on top of the plan fee, versus 30 x $0.60 x 3 months = $54 to warm your own for the same 90 days. What the extra $216 buys is the 14-day wait, at the cost of a 15-a-day cap that cannot be raised and domains EmailPal owns. Both the lease and warming figures exclude the plan fee.
04
A realistic timeline
Day 1: buy or connect domains, wait for DNS (minutes to a few hours depending on TTL and the registrar), create mailboxes, enable warming. Days 1 to 14: warming only. Verify the list, write a plain first email, create the campaign as a draft and fix launch warnings. Do not add campaign volume on top of the ramp.
Day 15: mailboxes are campaign-ready. Launch at about 5 cold emails per mailbox per day (150 a day across 30). Days 22 to 28: about 10 per mailbox (300). From day 29: up to 15 per mailbox (450) if the list is clean. Plan on about four weeks from purchase to full volume on fresh domains. An aged domain on the accelerated profile reaches the warming ceiling in about a week, but the campaign-ready flag is still set at 14 days of warming.
Campaign-ready is a 14-day calendar flag, not a lock. EmailPal marks it after 14 days of warming and shows the measured inbox rate beside it. Nothing blocks you from sending earlier: the campaign picker labels a warming mailbox as Warming up and the launch checklist warns that sending cold now may hurt deliverability. A mailbox can carry the flag and still land in spam, so read the inbox rate as well.
If a campaign cannot wait two weeks, pre-warmed inboxes are the alternative. They are leased at $3 a month on domains aged 90 days or more, can send 15 a day from the day you claim them, and keep warming running at no extra charge. See the page on starting without warm-up for the tradeoffs.
05
Where to do each step in the dashboard
Domains: search and register, or add a domain you own, and top up the domain balance (Billing or the domain search page). Mailboxes: create in bulk, select rows to turn warming on, and export credentials if you send from another tool. Warming: ramp state, campaign-ready and inbox rate. Engage: campaigns, leads, the launch checklist and analytics, with Unibox and CRM beside it for replies.
The domain balance is separate from the subscription card. In the API, POST /account/topup needs an admin-scoped key and returns a hosted payment page for $20 to $5,000. A domain purchase that the balance cannot cover buys nothing and returns 402 with the shortfall.
06
What stops sending automatically
EmailPal’s sequencer pauses a campaign when hard bounces pass 5% after at least 200 sends (the default, adjustable from 0.5% to 5%), and resuming runs the launch check again. Separately, a mailbox whose cold mail is rejected by receiving servers at 5% is paused, with a warning email at 3%. While a mailbox is paused, new SMTP mail from it is refused. These are guardrails for a list that should never have been sent, not a substitute for verification.
Authentication, warming and verification do not fix a scraped list, identical copy from every mailbox in the same hour, or a domain that is already blocklisted. Vary the first line, stagger send windows, and retire a burned name instead of trying to warm it back.
07
If you already use another sequencer
The infrastructure and the sequencer are separate. You can run steps 1 to 7 here and send the campaign from Instantly, Smartlead, lemlist or any tool that accepts SMTP and IMAP, using the credential export. In that case the launch check, auto-pause and campaign-level limits above apply to EmailPal’s own sequencer only. See the page on using EmailPal mailboxes with those tools.
Limits, prices and names, in one table
The figures this page relies on, so you do not have to hunt for them.
| Mailboxes per domain | 4 to 6 suggestedAbout 5. The form warns past about 10; not enforced on domains you own; pre-warmed bundles are fixed sets. |
| Cold volume per inbox | 15/day recommended; 100/day hard capThe cap is enforced per address at the mail server. Warming does not count toward it. |
| Campaign-ready flag | After 14 days of warmingInformational, not a lock. Set immediately on the no-ramp profile. |
| Warming | $0.60/inbox/moAbout 2 messages a day rising to about 20 on the standard profile. |
| Starter plan | $69/mo50 mailboxes and 50 domain slots included; 500 instant verification checks a day. |
| Growth plan | $189/mo200 mailboxes and 200 domain slots. |
| Scale plan | $499/mo600 mailboxes and 600 domain slots. |
| Extra mailbox | $1/moHard ceiling at 3x the included count. |
| Domains | $1 to $10 once each.xyz $1, .info $2, .biz $5, .com $10. Aged unwarmed domains start from $19. |
| Example: 6 domains x 5 mailboxes | 30 inboxes, about 450 emails a day$87/mo on Starter ($69 plan + $18 warming) plus $6 to $60 once for domains. |
| Pre-warmed inbox | $3/mo, 90-day minimum15 cold emails a day from day one; warming included; domains owned by EmailPal. |
| Time to full volume on fresh domains | About 4 weeks14 days of warming, then about 5, 10 and 15 per mailbox per day. |
| API budget | 1,000 requests an hourPolling spends it; use webhooks. |
| Records written automatically | MX, SPF (-all), DKIM RSA-2048 and Ed25519, DMARC p=rejectRe-verified against public resolvers. |
Checked against the product and the API on . Plans and limits change, so confirm in the docs before you build on them.
This is not for you if
- You need to send from existing Google Workspace or Microsoft 365 mailboxes. EmailPal’s mailboxes are hosted SMTP and IMAP on domains you register or connect, not Google or Microsoft seats, and campaigns do not send through OAuth-connected accounts.
- You need to send this week from a domain you own. A fresh domain needs at least 14 days of warming; the fast option is pre-warmed inboxes, which are leased on domains EmailPal owns.
- You need lead data. EmailPal verifies lists you bring and does not sell contacts.
- You want to send cold email from your main company domain. This setup assumes separate sending domains.
- You expect a guaranteed inbox placement. Infrastructure, warming and verification improve your starting position; copy, targeting and list quality still decide results.
- You need only a handful of mailboxes. The plan fee starts at $69 a month with 50 mailboxes included.
Common questions
How long does it take to set up cold email infrastructure?
Buying domains, waiting for DNS and creating mailboxes takes minutes to a few hours of elapsed time. The wait is warming: a new domain should have at least 14 days of warming before the first cold email, and reaching full volume of 15 a day per inbox takes about four weeks in total. Pre-warmed inboxes skip the 14 days.
How many domains and mailboxes do I need?
Divide your target daily volume by 15 to get mailboxes, then put 4 to 6 mailboxes on each domain. For about 450 emails a day that is 30 mailboxes across 5 to 8 domains. Starter’s 50 included mailboxes at 15 a day is 750 sends across roughly 9 to 13 domains.
Do I have to set up SPF, DKIM and DMARC myself?
Not on domains EmailPal registers, or on connected domains once you delegate nameservers. EmailPal writes MX, SPF with -all, DKIM at RSA-2048 and Ed25519 and DMARC at p=reject, and re-verifies them against public resolvers. On a manual domain you add the records from GET /domains/{id} yourself, including after a DKIM rotation.
How much does cold email infrastructure cost on EmailPal?
Plans start at $69 a month with 50 mailboxes included, extra mailboxes are $1 a month, warming is $0.60 per inbox per month, and domains are $1 to $10 once each. Six domains with five mailboxes each is about $87 a month plus $6 to $60 for the domains, with the sequencer, Unibox and CRM included.
Can I bring domains I already own?
Yes. Use mode connect on POST /domains, or add the domain in the dashboard. It costs nothing beyond a domain slot. Choose nameservers to delegate the zone to EmailPal, or manual to add the records yourself. Do not use a domain whose MX still has to receive your company’s regular mail.
Do I need a separate sequencer?
No. EmailPal includes a sequencer (it went live on 5 October 2026), a shared inbox and a CRM on every plan. You can still use Instantly, Smartlead, lemlist or any tool that accepts SMTP and IMAP by exporting credentials with an admin-scoped key. EmailPal’s launch check and auto-pause only cover campaigns run in its own sequencer.
Can an AI agent run these steps?
The same operations exist as MCP tools. The MCP server runs locally on your machine, EmailPal does not host an endpoint, and the @emailpal/mcp package is not yet published to npm, so use the REST API for these steps today.
Related
- Domains and mailboxes
- Email warming
- List verification
- Sequencer
- Pre-warmed inboxes
- API documentation
- Start sending cold email without warm-up
- How to warm up a new domain for cold email
- Scale cold email to 1,000 a day
- Cold email without risking your main domain
- Provision cold email mailboxes by API
- Use EmailPal mailboxes with Instantly, Smartlead or lemlist
- EmailPal vs Winnr
- All use cases
Build it on infrastructure that holds up
Domains, mailboxes, warming and verification over one REST API and MCP server, with the sequencer, Unibox and CRM on every plan.
No card to start — cancel any time.