Protect the primary domain, choose clearly related sending identities, keep registration and DNS under accountable control, authenticate every path, and define renewal and retirement before launch. Domain rotation is not a cure for unwanted sending.
Separate message streams for resilience
Critical account mail, permission-based marketing, support conversations, and prospecting have different audiences and failure modes. Separate domains or subdomains can keep an incident in one stream from disrupting password resets or customer receipts. The separation should be visible in monitoring, provider configuration, and incident response—not only in the From address.
Google recommends stable From identities by message category and, when multiple IPs are used, separating categories across those IPs. The intent is consistent classification and reputation, not frequent identity changes. [1]
Related does not mean deceptive
A recipient should be able to understand which company is writing. Avoid typo domains, third-party lookalikes, concealed redirects, fake employee identities, or wording that implies an existing relationship. The website, signature, From name, Reply-To, and legal sender should tell one coherent story.
The FTC’s U.S. guidance requires accurate header and routing information and non-deceptive subjects. Technical validity is not enough when the overall identity misleads the recipient. [2]
Write down the custody model
If an agency or infrastructure vendor registers the domain, the contract should say who owns it and what happens at termination. A domain that cannot be transferred, renewed, or secured independently is not merely a marketing asset; it is an operational dependency.
- Legal registrant and registrar account owner
- Authoritative DNS provider and scoped automation credentials
- Renewal payment method, renewal alert, and expiry recovery owner
- SPF, DKIM, DMARC, MX, return-path, and verification record owner
- Who may create mailboxes, reset credentials, or change forwarding
- Offboarding process, export rights, and transfer restrictions
Do not use a universal mailbox-per-domain formula
Rules such as “three inboxes per domain” or a fixed daily number are heuristics, not receiver guarantees. Capacity depends on message category, domain history, mailbox provider, receiving-network mix, relevance, reply behavior, complaint levels, content, and how quickly volume changes.
Start from the audience and safe schedule. Work backward to the number of sending identities, then add operational reserve so a paused mailbox does not force volume onto the others. If the required domain count looks absurd, the likely problem is campaign breadth, not insufficient rotation.
Plan the full lifecycle
Before sending, verify registration, nameservers, SPF, DKIM, DMARC, MX, TLS, forward and reverse DNS where applicable, and the role mailboxes used for postmaster, abuse, and reports. During operation, monitor authentication, renewal, replies, reputation, and queue behavior.
At retirement, stop new sends, keep inbound and unsubscribe processing available for an appropriate period, preserve suppression and audit records, remove obsolete authorization, and decide whether the domain will be retained defensively. Never let automatic expiration be the offboarding plan.
Common questions
Questions, answered plainly
Should cold outreach use the company’s primary domain?
Separating prospecting from critical customer and employee mail can reduce correlated risk. The alternate identity should still be truthful and clearly related to the company.
How many mailboxes should a sending domain have?
There is no receiver-approved universal number. Choose from safe campaign volume, provider limits, identity history, and operational reserve rather than a social-media formula.
Who should own a sending domain?
The contract should make legal ownership, registration custody, DNS control, renewal, and offboarding explicit. Avoid infrastructure that becomes hostage to an inaccessible vendor account.
Evidence
Sources and methodology
Product capabilities were checked against first-party documentation available on September 9, 2026. Policies, plans, and prices can change; verify them before buying. General guidance is educational and is not legal advice.
- Email sender guidelines Google. Authentication, DNS, spam-rate, formatting, unsubscribe, and volume guidance for Gmail.
- CAN-SPAM Act: A Compliance Guide for Business U.S. Federal Trade Commission. Official U.S. guidance for commercial email, including B2B messages.
- DMARC overview DMARC.org. How DMARC builds on SPF and DKIM to add alignment, policy, and reporting.
Your agent can do the thinking.
The infrastructure still needs a grown-up.