Skip to content
← BlogDeliverability7 min read

Secondary domains for cold email: never send cold from your main domain

The standard 2026 setup: lookalike secondary domains for outbound, 2-3 mailboxes each, round-robin under 40 sends a day, with the DNS records most guides skip.

By David Lara, Founder

Founder-reviewed ·How we research and correct articles

Here’s the rule every experienced sender treats as non-negotiable and every first-timer learns by burning something: your primary domain never sends cold email. Not because cold email is dirty — because sender reputation is attached to the domain, and your primary domain also carries your invoices, your password resets, your support threads and every reply your company will ever send. You don’t gamble that on outbound experiments.

Diagram: the main company domain protected at the top, three lookalike secondary domains below it dedicated to cold outbound, each with mailboxes capped at 40 sends per day, connected by a round-robin rotation arc

The setup, end to end

1 · Buy lookalike domains

Close variants of your real name: company.io, getcompany.com, trycompany.com. Rules of thumb:

  • Recognizable at a glance — the prospect should read it as you. Weird hyphenations and unrelated names read as phishing.
  • Boring TLDs win. .com, .co, .io. Bargain-bin TLDs arrive pre-tainted by the spammers who got there first.
  • One domain per ~2–3 mailboxes, ~80–120 sends/day. Need more volume? Add domains, not volume per domain. The math lives in how many cold emails per day per mailbox.

Check the age and history of anything you buy — a previously-owned domain can come with baggage. Two minutes in the WHOIS lookup and the blocklist checker before paying.

2 · Authenticate every domain like it’s your main one

Secondary doesn’t mean sloppy. Since the Gmail/Yahoo rules of 2024, mail from unauthenticated domains isn’t filtered — it’s increasingly rejected outright. Each sending domain needs:

  • SPF — one lean record, under the 10-lookup budget (generator, free)
  • DKIM — 2048-bit key from your sending provider (checker)
  • DMARC — start at p=none with reports on, and actually read them (generator, and here’s how to read the reports)
  • MX + a real mailbox — a domain that can’t receive mail looks disposable, and you need the replies anyway.

One pass through the domain health checker confirms all four in seconds.

3 · Redirect the naked domain

Point getcompany.com at your real website with a 301. A prospect who types the domain into a browser should land somewhere real — a parked page under an email asking for their time is exactly the trust-killer it looks like. Curious prospects check.

4 · Warm up before anything sends

A fresh domain plus instant volume is a common way campaigns fail in week one. Use two weeks as the minimum observation period for one low-volume mailbox and plan four to eight weeks for a new or materially higher-volume domain. The full decision framework is in how long domain warmup takes, and the warmup calculator turns it into a day-by-day schedule. We watched what happens when you rush this on our own 11-day-old domain so you don’t have to.

Warmup on Norbelys is included, with no per-mailbox warmup charge. Some outreach platforms also include warmup; dedicated products may charge by mailbox, which compounds across a 3-domain × 3-mailbox setup.

5 · Rotate round-robin, not priority

With multiple mailboxes in a campaign, distribute sends evenly across the pool, not “fill mailbox one, overflow to two.” Round-robin keeps every mailbox comfortably under its ceiling; priority-order quietly overworks the first inbox in the list until its reputation erodes — the kind of decay nobody notices until replies are already down.

Keep per-mailbox volume under ~40/day with human-looking gaps between sends. Norbelys paces every mailbox with its own budget and jitter so a campaign can’t accidentally strip-mine one sender.

Why isolation actually protects the main domain

It’s worth being precise about what “reputation” means here, because the reasoning behind domain isolation only makes sense once the mechanism is clear. Mailbox providers don’t track reputation at the company level — they track it per sending domain and, to a real extent, per sending IP. A domain’s reputation is built from the pattern of behavior specific to it: bounce rate, complaint rate, engagement, authentication consistency, all accumulated over that domain’s own sending history. None of that transfers automatically between domains, which is exactly why isolation works as a strategy: whatever happens on getcompany.com stays scoped to getcompany.com, and your main domain’s years of clean transactional and support-email history remain untouched by it.

That containment cuts both ways, and it’s worth being honest about the downside. A secondary domain also starts from zero — it inherits none of your main domain’s trust, which is why the warmup step isn’t optional scaffolding, it’s the only way the new domain earns the standing that lets its mail actually land. The upside is that a bad outcome on one secondary domain — a list that turned out to be dirtier than expected, a complaint spike from a campaign that ran too hot — costs you that one domain’s sending capacity, not your ability to send a password reset or an invoice that a customer is actively expecting. Losing a secondary domain to a burned reputation is recoverable: retire it, buy another, warm it up again. Losing your main domain’s sending reputation because it got treated as a cold-outbound testing ground is a much longer, much more expensive repair, precisely because everything else your company sends depends on that same domain staying trusted.

What stays on the main domain

Everything that isn’t cold: transactional mail, newsletters to opted-in lists, support, and — opinions differ, ours is firm — your warm follow-up after a meeting is booked. Once a prospect replies and the relationship is real, moving the thread to your primary domain is honest and tidy.

The failure modes to watch

  • Bounce rate over 2% on a young domain does outsized damage — verify the list before it teaches Gmail who you are. On Norbelys, imports are verified automatically, no credits, included.
  • Complaints over 0.3% end the domain’s useful life quickly — the complaint-rate math explains why the auto-pause thresholds exist.
  • All domains behaving identically (same volume, same schedule, same copy) makes the pool look like what it is. Vary naturally.
  • Forgetting the reports. DMARC on the secondaries isn’t bureaucratic — it’s your early warning that a domain is being spoofed or leaking. Ours arrive as plain-language answers, not XML.

The infrastructure isn’t glamorous, but it’s the difference between outbound as a system and outbound as a series of burned domains. Set it up once, properly, and the copy finally gets a fair test.

Secondary domains — quick answers

How many secondary domains does a typical outbound program need?

It scales with sending volume, not team size. At roughly 2-3 mailboxes and 80-120 sends per day per domain, a program that needs 500 sends a day is looking at 4-6 domains, not one domain pushed far past its safe ceiling. Adding domains as volume grows keeps every individual domain's reputation profile in the range that stays deliverable.

Should each secondary domain use a completely different name, or close variants of the same one?

Close, recognizable variants of your real company name — the goal is a prospect reading it as legitimately you at a glance, not a random unrelated name that reads as unrelated spam infrastructure. A domain that requires explanation before a prospect trusts it undermines the exact credibility the setup is meant to protect.

Do secondary domains need their own privacy policy or legal pages?

They don't need a full site — a simple redirect to your real website (a 301, not a blank parked page) is standard and expected. What they can't skip is the functional requirements: working authentication records, a real mailbox that receives replies, and a domain that doesn't look abandoned or disposable if a curious prospect visits it directly.

Is it ever safe to send cold email from the main domain if volume is very low?

Even at low volume, the risk is asymmetric — a small cold-outbound test that goes wrong still risks the same domain your invoices, password resets, and every existing customer relationship depend on, for a savings that amounts to skipping a one-time domain purchase and setup. The isolation is worth it even for small-scale testing, not just at production volume.