Mailbox provisioning is a sequence of containment, setup, and proof. Put cold volume on secondary domains so it can be isolated from the primary domain.1 Complete authentication before sending.2 Warm each inbox before live campaigns begin.3 The easy mistake is to treat warmup as the whole protection plan. Warmup is only one input into sender reputation; authentication, recipient expectations, complaint rates, content, infrastructure, and sending history also affect it, and no tool can override provider filtering decisions.4, 5 Build the setup so each decision has a clear gate: domain choice, mailbox count, account access, authentication, warmup, and launch.
Choose the domain boundary
Decide what each domain is allowed to send before you create accounts. This prevents the mailbox plan from quietly becoming a plan for putting every type of mail on the same reputation.
A flagged sending domain can harm future transactional and personal email as well as cold email.6 Keep the cold sending surface separate from the mail that carries ordinary business communication. Record the domain boundary before provisioning begins, then ask which mail must remain on the primary domain and which mail belongs on the outbound domain.
Move on when the domain has a defined purpose and the people responsible for provisioning agree on that boundary.
Set the mailbox and domain count
Answer the capacity question before buying licenses or creating users. The count should follow the sending plan, while the domain rule limits how much pressure one domain carries.
Use one email account per domain as the default for cold email.7 For a planning estimate, divide the daily send target by 50 to estimate the inboxes required and by 100 to estimate the domains required.8 If the formula gives fewer domains than inboxes, increase the domain count so the one mailbox per domain rule stays intact.
Ask what daily send target the campaign needs, then check whether the resulting mailbox and domain pool fits the budget and the provisioning workload. Move on when every planned mailbox has a domain assigned before anyone starts creating accounts.
Create the mailbox and assign access
Create a real sending identity first, then connect the access and settings that the campaign needs. Keep account creation separate from later changes so a missing creation-time attribute does not get mistaken for a failed mailbox.
Use a real mailbox connected to the sending domain.9 Attributes that cannot be set during creation require a two-step sequence: create the account first, then modify it.10
For an Office365 setup, have the Office365 administrator complete the documented setup steps.11 The administrator can select the applicable account or use the Use Another Account option to add or create an account.12 After the connection succeeds, users with the sending platform license can connect their Office365 mail accounts to the platform.13
Treat the license as a gate before asking a user to connect. Delegated inbox access grants permission to manage email only,14 so verify sending authorization separately when access has been delegated.
Move on when the mailbox exists, the intended user has the required access, and the connection succeeds without relying on an informal shared credential.
Finish authentication before sending
Authentication is the technical launch gate. Check it while the mailbox is still unused, when a failed record or connection is easier to isolate.
Configure MX, DKIM, SPF, and DMARC correctly before sending any cold email.2 For mail sent to personal Gmail accounts, all senders need SPF or DKIM.15 Complete the full domain and mailbox setup before prospects enter the campaign.16
Use a checklist for each domain and mailbox, then verify that every required record is present and resolving as expected. Keep the mailbox out of live outreach until the checklist passes. Move on when the sending identity, domain records, and campaign connection all point to the same setup.
Warm the mailbox and watch the signals
Warmup is a controlled ramp in sending history, followed by a decision based on delivery signals. Give the mailbox time to establish a pattern, then let its behavior decide whether the campaign can advance.
Warmup means gradually establishing sending history from a new or inactive setup.17 Warm every new inbox for at least 3 weeks before live campaigns begin.3 During that period, authenticate the mail, send wanted messages consistently, increase volume slowly, and monitor bounces, deferrals, complaints, and reputation signals; reduce volume when those signals worsen.18
Set a launch review around the end of the warmup period. Look for worsening delivery or complaint signals before increasing campaign activity, and pause the increase when the signals move in the wrong direction. Move on when the mailbox has completed the minimum warmup period and the monitored signals support a controlled launch.
What not to do
These are the shortcuts that create false confidence during provisioning.
- Do not treat a universal 28-day mailbox schedule as provider guidance; mailbox providers do not publish one.19
- Do not treat simulated traffic from automated warmup networks as proof that inbox placement will improve; providers do not certify those networks or promise that result.20
- Do not use a warmup tool as a substitute for permission, list hygiene, authentication, or provider compliance.21
- Do not add multiple email accounts to one domain without accounting for the higher domain volume and greater blacklist risk.22
You can now provision each mailbox against a defined domain boundary, access requirement, authentication checklist, and warmup gate. Keep those decisions in a setup record and advance a mailbox only when its own checks pass.