Deliverability is simply whether your email reaches the inbox or gets filtered into spam. For recruiters it comes down to a handful of basics: authenticating your domain with SPF, DKIM, and DMARC, sending from a real and reputable mailbox, keeping volume sane, mailing clean lists, and giving people an easy way to unsubscribe.
You can write the best cold email in your market, but if it never reaches the hiring manager's inbox, none of it matters. This is the part of cold outreach recruiters tend to ignore, right up until reply rates quietly collapse and nobody can say why. The good news: deliverability isn't magic, and you don't need to be an email engineer to get it right. This guide explains what actually decides whether your outreach lands, in plain English.
What "deliverability" actually means
There's a difference between an email being delivered and being delivered to the inbox. When you hit send, the receiving mail provider, Gmail, Outlook, a company's own server, makes a fast decision: accept it to the inbox, drop it in spam, or reject it outright. Deliverability is the odds of that decision going your way.
Providers make that call using signals they trust. Is this sender who they claim to be? Do people who get their mail usually want it, or do they mark it as junk? Is the sending pattern normal, or does it look like a machine blasting strangers? Every recommendation below is really just a way of sending the right signals.
Authentication: SPF, DKIM, and DMARC
These three are the foundation, and they are the part recruiters most often skip. They're a set of DNS records that prove your email genuinely comes from your domain and hasn't been forged. Modern providers increasingly treat missing authentication as a reason to send you straight to spam, so this is non-negotiable.
Here's what each one does, without the acronym soup:
| Record | What it does | Who sets it up |
|---|---|---|
| SPF | Lists which mail servers are allowed to send email for your domain. The receiver checks whether the message came from an approved server. | You (or your IT person), as a DNS record on your domain. |
| DKIM | Adds a cryptographic signature to each message so the receiver can verify it really came from your domain and wasn't altered in transit. | Your email provider generates the key; you publish it in DNS. |
| DMARC | Tells receivers what to do when SPF or DKIM fails, ignore, quarantine, or reject, and lets you receive reports on who's sending as you. | You, as a DNS record, once SPF and DKIM are in place. |
Think of it this way: SPF is the guest list, DKIM is the tamper-proof seal, and DMARC is the instruction to the receiver on what to do if the seal or the list doesn't check out. You want all three passing. If you use Google Workspace or Microsoft 365, both publish clear setup guides, and DKIM in particular is usually a couple of clicks plus one DNS entry.
The one thing to do first: if you send cold email from a domain without SPF, DKIM, and DMARC set up, fix that before anything else. No subject-line tweak or clever copy will outrun failed authentication, providers filter unauthenticated cold mail hard.
Reputation: the score you can't see
Once you're authenticated, providers track your reputation, a running judgment about both your domain and the specific mailbox you send from. Reputation is built slowly and lost quickly. It goes up when recipients open, reply, and keep your mail; it goes down when they delete without reading, mark you as spam, or when you hit dead addresses that bounce.
This is why a brand-new domain that starts blasting cold email tends to struggle: it has no track record, so providers treat it with suspicion. It's also why one bad week, a big blast to a stale list that triggers spam complaints, can drag down everything you send afterward, including your legitimate replies to warm prospects.
Why sending from your own Gmail or Workspace usually wins
A lot of cold-email advice tells you to buy a separate "sending domain," warm it up for weeks, and send from that instead of your real inbox. For high-volume sales teams pushing thousands of emails a day, there's a logic to isolating that risk. For an independent recruiter or a boutique firm sending modest volumes, it's usually the wrong trade.
Your existing Gmail or Google Workspace mailbox already has something a fresh cold-email domain doesn't: established reputation. You've been sending and receiving real conversations from it for months or years. Providers already trust it. A brand-new throwaway domain starts from zero and has to earn that trust through a slow, error-prone warmup, and if you get the warmup wrong, you've burned the domain before you've booked a single meeting.
For low-to-moderate recruiter volumes, sending from your own reputable inbox means your outreach inherits that existing trust, your replies come from the address people expect, and you skip the whole cold-domain grind. The tradeoff is that you must protect that reputation, which brings us to volume.
Volume and pacing: why blasting flags you
Real people don't send 500 individual emails in an hour. Spammers do. When a mailbox suddenly fires off a huge batch of near-identical messages to strangers in a short window, that pattern itself looks automated and abusive, regardless of how good the content is.
The fix is to keep volume sane and spread sends out so they look human. A few practical habits:
- Cap your daily volume. Modest, steady sending protects your reputation far better than occasional big blasts.
- Space sends out. Drip messages across the day with natural gaps rather than firing them all at once.
- Ramp up gradually. If you're increasing volume, do it slowly over time instead of jumping tenfold overnight.
- Watch the response. If opens drop or spam complaints tick up, pull back rather than pushing harder.
For recruiters this is rarely a real constraint, you're targeting a focused list of companies you actually want as clients, not carpet-bombing a purchased list of ten thousand contacts.
Spam triggers to avoid
Filters also read the message itself. You don't need to be paranoid about every word, but a few patterns reliably hurt you:
- Spammy language. All-caps subject lines, exclamation-point pileups, and hype words ("GUARANTEED," "act now," "free money") read as junk.
- Image-heavy emails. A message that's one big image with barely any text is a classic spam pattern. Cold outreach should be mostly plain text anyway, it feels personal.
- Too many links. Stuffing an email with links, or using shady link shorteners, raises flags. One relevant link is plenty for a first touch.
- No unsubscribe or physical address. Legitimate senders identify themselves and offer an opt-out. Its absence signals the opposite.
- Misleading subject lines. "RE:" on an email that isn't a reply, or bait-and-switch subjects, erode trust fast and invite complaints.
List hygiene and bounces
Where you get your list matters as much as what you send. Emailing addresses that don't exist produces bounces, and a high bounce rate is one of the clearest signals to a provider that you're sending to a list you didn't verify, a hallmark of spam. A wave of bounces can damage your reputation on its own.
Keep your list clean: source addresses carefully, remove obvious junk, and stop mailing anyone who has bounced or asked out. Never buy scraped lists, they're full of dead addresses and spam traps, and one campaign to a bad list can undo months of good sending. For recruiters, targeting a smaller list of real, current hiring managers beats a giant list of stale contacts every time.
The unsubscribe link isn't optional
A working, honest unsubscribe does two jobs. First, it keeps you compliant: the US CAN-SPAM Act requires commercial email to include a clear opt-out and a valid physical mailing address, to honor opt-out requests promptly, and to avoid deceptive headers and subject lines. Even cold B2B recruiting outreach falls under these rules.
Second, and this is the deliverability angle people miss, an easy unsubscribe protects your reputation. When someone who doesn't want your email can leave with one click, they do that instead of hitting "mark as spam." Spam complaints hurt you far more than an unsubscribe ever will, so making the opt-out easy is genuinely in your interest.
How GridMail handles this for you
Most of what's above is exactly the plumbing recruiters don't want to think about. GridMail is built to handle it: it sends from your own Gmail or Google Workspace, so your outreach inherits that inbox's existing reputation instead of starting a fresh cold domain from zero. It paces your sends so they look human rather than like a blast, and every email includes a real, working unsubscribe so you stay compliant and keep spam complaints down. In practice, that means you skip the separate-sending-domain warmup grind entirely, there's a fuller walkthrough of why in skip the DNS/warmup setup, and the FAQ covers the specific deliverability and compliance questions.
That's a deliberate design choice for independent recruiters and boutique firms, and the about page explains the reasoning. It's also the main difference from tools that require a separate sending domain like Smartlead, those are built for high-volume sales teams that isolate risk on throwaway domains, which is overkill (and a hazard) at recruiter volumes.
Reach the inbox without the deliverability headache
GridMail sends from your own inbox, paces your outreach, and includes a real unsubscribe, so your recruiting emails land where hiring managers actually read them. Get started, plans from $25/mo.
Get started