Cold email without risking your main domain
Send cold email from secondary domains so your main domain stays clean: naming, redirects, DNS isolation, 5 mailboxes per domain and a fleet from about $84 a month.
The short answer
Send cold email from separate secondary domains and never from your main company domain, so a spam-folder or blocklist problem lands on a domain you can replace instead of the one that carries your website, support and transactional mail. A fleet of 5 secondary domains with 5 mailboxes each costs about $84 a month on EmailPal ($69 Starter plus $15 warming) plus about $50 once for the domains, and sends about 375 cold emails a day at 15 per inbox. EmailPal writes SPF, DKIM, DMARC and MX on each domain you add automatically, and does nothing to a domain you do not add.
Keep your main domain for the website, company email and transactional mail, and send cold email only from registered lookalike domains such as tryacme.com or acmehq.com. Put about 5 mailboxes on each, point the domain’s website at your real site with a redirect, and let EmailPal write the authentication records. Reputation is tracked per domain, so a filtered secondary domain costs you that domain’s volume (75 emails a day at 5 mailboxes and 15 each) and about $10 plus two weeks of warming to replace. It does not hide who you are: recipients and complaints still reach your company name, so the list and the copy still matter.
How it works, step by step
Step 1
Decide what the main domain is for, and keep cold email off it
Reserve the main domain for the website, company mailboxes and transactional mail such as password resets and receipts. Do not add it to EmailPal as a sending domain. EmailPal points a sending domain’s MX at its own servers and writes SPF with -all and DMARC p=reject, which suits a sending-only domain and would break a domain that also carries your company’s mail.
Step 2
Choose secondary names that read like a company
Use your brand with a short prefix or suffix, such as tryacme.com, getacme.com or acmehq.com. Avoid “mail”, “outreach” or “blast” in the name, avoid long strings of hyphens or digits, and never use another company’s name. A conventional TLD such as .com costs a few dollars more than the cheapest options and is the conservative choice. A separately registered domain is cleaner than a subdomain of your main domain.
Step 3
Register or connect the domains
Register new domains through EmailPal (from $1 one-time, .com about $10), connect a spare domain you already own (free, uses a domain slot), or buy an aged unwarmed domain (from $19). POST /domains accepts up to 50 names per call; send an Idempotency-Key header because a purchase spends from the prepaid balance. DNS is written and then re-checked against public resolvers.
POST /api/public/v1/domainsbashcurl -X POST https://www.emailpal.io/api/public/v1/domains \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Idempotency-Key: secondary-domains-001" \ -H "Content-Type: application/json" \ -d '{ "mode": "purchase", "domains": ["tryacme.com", "getacme.com", "acmehq.com"] }'Step 4
Point each domain’s website at your real site
On the domain page, set the Website field to your main site’s https URL, or call set_redirect. Visitors to the apex and www are sent there with the path and query kept, and the certificate is issued for you. The redirect cannot change a mail record. It works on domains whose nameservers point at EmailPal, takes about a minute to take effect, and is refused if the domain already serves a different website.
POST /api/public/v1/domains/{id}bashcurl -X POST https://www.emailpal.io/api/public/v1/domains/dom_91af22 \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Content-Type: application/json" \ -d '{"action": "set_redirect", "redirect_url": "https://www.acme.com"}'Step 5
Create about 5 mailboxes per domain and turn warming on
Create about 5 mailboxes on each domain (4 to 6 is the suggested range) with real-looking names. Turn warming on at $0.60 per inbox per month and send no cold email for 14 days. Spread volume across the domains rather than adding mailboxes to one.
POST /api/public/v1/mailboxesbashcurl -X POST https://www.emailpal.io/api/public/v1/mailboxes \ -H "Authorization: Bearer $EMAILPAL_API_KEY" \ -H "Idempotency-Key: secondary-mailboxes-001" \ -H "Content-Type: application/json" \ -d '{ "domain_id": "dom_91af22", "count": 5, "pattern": "first.last", "warming": true }'Step 6
Keep the two worlds apart in the email itself
Send cold email only from the secondary domains and keep every other sender (marketing platform, billing system, support desk) on the main domain. Use plain text, few links, and one clear sender identity. Do not send the same body from every mailbox on a domain in the same hour.
Step 7
Monitor each domain and retire the ones that get filtered
Read inbox rate, warming state and DNS status per mailbox at least weekly. If a domain’s placement collapses, pause its mailboxes, stop adding volume anywhere, fix the list or the copy, and replace the domain rather than trying to rescue it. To release a domain, delete its mailboxes first.
01
Why a secondary domain, and what it actually protects
Mailbox providers score reputation by domain as well as by address and IP. Cold email carries more complaints, more bounces and more spam-folder placement than mail to people who asked for it, so a domain that sends it is the domain most likely to be filtered. If that domain is the one that also sends password resets and support replies, those start landing in spam too. A secondary domain moves that risk onto a name you can replace.
This is standard cold-email practice rather than an EmailPal invention, and EmailPal’s help center recommends it. What it protects is the sending and authentication reputation of your main domain. It does not protect the brand: recipients see your name and company in the email, a complaint is about you, and some filters weigh the links in the body. Keep the list verified and the copy plain, because isolation limits the blast radius and does not remove the cause.
02
Naming and the redirect
Pick names a reasonable recipient would accept as yours: your brand plus a short word, in a conventional TLD, with no bulk-sender vocabulary. Cheaper TLDs from $1 exist, but the saving is a few dollars against a $69 plan, so choose the conservative option. Do not register a typo of someone else’s brand, and do not reuse a name that was already filtered.
A recipient who types the secondary domain into a browser should find your real company. EmailPal’s Website setting redirects the apex and www to a URL you choose, with a certificate issued automatically, and until you set it the domain shows a landing page. A plain HTTPS redirect is fine; a thin page that repeats your email copy is not. The setting is a single URL and nothing else, so it cannot damage SPF, DKIM, DMARC or MX. It is not available on pre-warmed pool domains, which EmailPal owns.
If you already own a spare domain and bring it, either delegate its nameservers or paste the records EmailPal shows. Do not keep another sender’s SPF include on the same name, because SPF allows only 10 DNS lookups and a second stack can break it.
03
DNS isolation
Every sending domain has its own records. EmailPal writes SPF with a hard fail (-all), two DKIM keys (RSA-2048 and Ed25519), DMARC p=reject and MX for each domain you register or delegate, then re-verifies them from public resolvers. Nothing is written to a domain you did not add, so your main domain’s DNS stays with whoever manages it today.
Do not put cold email and company mail on the same domain. The MX on a sending domain points replies at EmailPal. A domain that also needs Google Workspace or Microsoft 365 to receive mail is the wrong domain to send cold email from, and SPF -all with DMARC p=reject would reject your own company mail from any sender it does not list. The same applies to a subdomain such as outreach.acme.com: the help center says it can work, but it often inherits trouble from the parent and still puts the brand at risk, so a separately registered domain is cleaner.
Domain separation covers domain reputation, not IP reputation. EmailPal runs isolated IP pools so one customer’s list does not define another’s, and dedicated IPs are $20 a month on Growth and Scale. Transactional mail sent through another provider does not share IPs with your cold mail in any case.
04
Mailboxes per domain
About 5. EmailPal’s mailbox form suggests 4 to 6 per domain and warns once a domain passes about 10, because concentrating volume concentrates the risk that one filter decision takes everything. 5 is a sensible planning figure. At the recommended 15 cold emails per inbox per day, 5 mailboxes send 75 a day from one domain.
Providers correlate mailboxes on the same domain, so if one address collects complaints its siblings feel it. EmailPal will let you create more than 5 on a domain you own; that is a reputation choice, not a feature. To send more, add domains, not mailboxes on one name.
05
What happens when a domain is filtered
Blast radius is one domain. With 5 mailboxes at 15 a day, losing one domain removes 75 emails a day. In a fleet of 10 domains that is 10% of capacity, and in a fleet of 5 it is 20%. Your main domain, your other secondary domains and your transactional mail are unaffected, because their reputations are separate.
EmailPal’s automatic controls work at the campaign and mailbox level. A campaign pauses at 5% hard bounces after at least 200 sends, a mailbox is paused at 5% rejected mail with a warning at 3%, and a campaign pause does not stop your other campaigns. Whether to retire a domain is your decision, informed by the inbox rate and bounce numbers. Restarting warming does not reset a domain’s reputation, so a burned name is retired.
To retire a domain, delete its mailboxes, then release it. Releasing is irreversible, is not refunded, stops renewal and discards the domain’s age and sending history. Replacing it means a new domain of about $10 and about 14 days of warming before you route volume to it.
06
Reputation monitoring that does not need guesswork
Inside EmailPal, open the mailbox and read its inbox rate, warming state (Slow-Ramp or blocked means placement is poor) and DNS status. Warming sends to a network of real Gmail, Outlook and Yahoo inboxes that report where each message landed, so the inbox rate is a measurement rather than an estimate. campaign-ready is a 14-day flag and not a lock, so read the inbox rate beside it.
Outside EmailPal, Google Postmaster Tools works on a domain you own once you have enough Gmail volume to appear there. Blocklist checkers are a secondary signal, and random listings on brand-new domains are common and often temporary. Do not rotate domains as a hobby; rotate when placement and complaints say the name is burned.
07
Cost of a secondary-domain fleet
Prices are the published ones: Starter $69 a month with 50 mailboxes and 50 domain slots, extra mailboxes $1 each, warming $0.60 per inbox per month, and domains a one-time registration price paid from a prepaid balance (.xyz $1, .info $2, .biz $5, .com $10 per the help center; domain search returns the exact quote). The plan fee is the floor, so the domains are a small share of the total.
3 domains with 4 mailboxes each is 12 mailboxes: $69 + 12 × $0.60 = $76.20 a month and 180 cold emails a day, plus 3 × $10 = $30 once. 5 domains with 5 each is 25 mailboxes: $69 + $15 = $84 a month and 375 a day, plus $50 once. 10 domains with 5 each is 50 mailboxes: $69 + $30 = $99 a month and 750 a day, plus $100 once. 20 domains with 5 each is 100 mailboxes: $69 + 50 extra mailboxes ($50) + $60 = $179 a month and 1,500 a day, plus $200 once. Extra mailboxes add matching domain slots, so 20 domains fit.
If you would rather not own the names at all, pre-warmed inboxes are leased on domains EmailPal owns, at $3 per inbox per month with a 90-day minimum and 15 cold emails a day from day one. That is complete separation from your main domain, with no naming control, no ownership and no redirect.
08
What not to do
Do not send cold email from the domain that sends your transactional mail. Do not send cold email from the main domain “just for a small test”, because reputation does not reset afterwards. Do not put 20 mailboxes on one secondary domain, do not send identical copy from every mailbox in the same hour, and do not pad the secondary domain’s website with the same text as the email.
Do not treat the secondary domain as a mask. The sender name, the signature and the unsubscribe text all say who you are, and they should. Do not skip list verification because the domain is disposable: a bounce storm can burn a domain in days, and replacing it costs two weeks of warming.
Limits, prices and names, in one table
The figures this page relies on, so you do not have to hunt for them.
| Mailboxes per secondary domain | About 5 (4 to 6)Dashboard suggests 4 to 6 and warns past about 10. |
| Cold volume per inbox | 15 a day recommendedHard ceiling of 100. 5 mailboxes send 75 a day from one domain. |
| Domain registration | From $1 one-time.xyz $1, .info $2, .biz $5, .com $10. Aged unwarmed domains from $19. |
| Bring your own spare domain | FreeUses one domain slot. No registration fee. |
| Fleet: 3 domains x 4 mailboxes | $76.20/moStarter $69 + warming 12 × $0.60. 180 a day. Domains $30 once. |
| Fleet: 5 domains x 5 mailboxes | $84/moStarter $69 + warming 25 × $0.60. 375 a day. Domains $50 once. |
| Fleet: 10 domains x 5 mailboxes | $99/moStarter $69 + warming 50 × $0.60. 750 a day. Domains $100 once. |
| Fleet: 20 domains x 5 mailboxes | $179/moStarter $69 + 50 extra mailboxes + warming 100 × $0.60. 1,500 a day. Domains $200 once. |
| Warming | $0.60/inbox/mo14 days before the campaign-ready flag. The flag is informational, not a lock. |
| Website redirect | 302, https onlyApex and www. Path and query kept. About a minute. Nameserver-delegated domains only. |
| Authentication written per domain | SPF -all, DKIM x2, DMARC p=reject, MXDKIM is RSA-2048 and Ed25519. Re-verified on public resolvers. |
| Campaign bounce auto-pause | 5% after 200 sendsMailbox pause at 5% rejected, warning at 3%. |
| Dedicated IP | $20/moGrowth and Scale. |
Checked against the product and the API on . Plans and limits change, so confirm in the docs before you build on them.
This is not for you if
- You only send a few one-to-one emails to people you already know. A secondary domain adds setup for no benefit at that volume.
- You expect a secondary domain to hide your company. Recipients see your name and company, and complaints reach you either way.
- You want to send from existing Google Workspace or Microsoft 365 mailboxes on your main domain. EmailPal sends from its own hosted SMTP and IMAP mailboxes on domains it hosts, and there is no way to connect an existing Gmail or Outlook mailbox, even for warming.
- You want to own and name the domain and also skip warming. Pre-warmed inboxes are on domains EmailPal owns, with no custom names, and they do not support the website redirect.
- You want a hands-off service that decides when to replace a filtered domain. Campaign and mailbox pauses are automatic; the decision to replace a domain is yours.
Common questions
Why should I not send cold email from my main domain?
Because reputation is tracked per domain, and cold email earns more complaints, bounces and spam-folder placement than other mail. If your main domain is filtered, your website mail, support replies and transactional mail suffer with it. A secondary domain of about $10 can be replaced; your main domain is much harder to replace.
Can I use a subdomain like outreach.acme.com instead of a new domain?
You can, but EmailPal’s help center advises against it. A subdomain often inherits trouble from the parent and still puts the brand at risk, so a separately registered domain is cleaner. It also keeps SPF, DKIM, DMARC and MX away from the main domain’s records.
Should my secondary domain redirect to my website?
A plain HTTPS redirect to your real site is fine and helps a curious recipient find your company. Do not host a thin page full of the same copy as the email. In EmailPal set the Website field on the domain page, or call set_redirect on POST /domains/{id}. It redirects the apex and www, keeps the path and query, and cannot touch a mail record.
How many mailboxes should I put on each secondary domain?
About 5. EmailPal’s mailbox form suggests 4 to 6 per domain and warns past about 10. At 15 cold emails per inbox per day, 5 mailboxes send 75 a day from one domain. To send more, add domains.
What happens if one secondary domain gets filtered?
Only that domain is affected. At 5 mailboxes and 15 a day you lose 75 emails a day, and your main domain and other secondary domains keep their own reputations. Pause its mailboxes, fix the list or the copy, and replace the domain, which costs about $10 and about 14 days of warming. Restarting warming does not reset a burned domain.
How much does a fleet of secondary domains cost?
On Starter, 5 domains with 5 mailboxes each is about $84 a month ($69 plan plus $15 warming) and about $50 once for .com domains, sending about 375 a day. 10 domains with 5 mailboxes each is about $99 a month and $100 once. The plan fee is the floor; domains are the small part.
Can I use the same domain for cold email and transactional email?
No. A sending domain on EmailPal has MX pointing at EmailPal, SPF -all and DMARC p=reject, which would conflict with another sender on the same name. Cold email also carries the reputation risk you want away from transactional mail. Keep each on its own domain.
Related
- How to set up cold email infrastructure
- Scale cold email to 1,000 a day
- How to warm up a new domain for cold email
- Why cold emails go to spam: a checklist
- Start sending cold email without warm-up
- Domains and mailboxes
- Warming
- Pre-warmed inboxes
- API documentation
- Use EmailPal mailboxes with Instantly, Smartlead or lemlist
- All use cases
Build it on infrastructure that holds up
Domains, mailboxes, warming and verification over one REST API and MCP server, with the sequencer, Unibox and CRM on every plan.
No card to start — cancel any time.