Deliverability
Jun 20, 2025
Don't Put All Your Emails in One Basket: Why Infrastructure Diversity Matters
Route every email through one provider and a single flag takes the whole campaign down. Why senders spread infrastructure the way investors spread risk.

Running all of your email through one domain and one provider means a single spam flag can take down sales, support, and customer communication at the same time. Infrastructure diversity separates cold outreach from business-critical email onto different domains, different providers, and different IPs, so that one bad campaign costs you a slice of capacity instead of your entire ability to send.
The Single Point of Failure Problem
Most B2B teams are one bad week away from losing their email. The setup that gets them there looks completely reasonable:
Everything through one provider. Google Workspace or Microsoft 365 handles sales, marketing, support, and transactional mail.
One domain for every kind of email. Cold outreach and invoices share a reputation.
No fallback. When the primary is throttled, there is nowhere to move.
Shared IP reputation. One aggressive campaign taints everything that follows.
The failure mode is not that cold outreach stops working. It is that cold outreach takes everything else down with it. When a company's primary domain gets flagged for aggressive sending, the damage is not confined to the campaign that caused it. Password resets, invoices, support replies, and renewal conversations all run through the same reputation, and they all start landing in spam at the same time.
That is the asymmetry worth internalising. The upside of pushing your main domain harder is a few hundred extra sends. The downside is your company's ability to communicate with its existing customers.
Why the Same Email Behaves Differently at Every Provider
Deliverability is not one verdict. It is a separate verdict from every receiving system, each with its own filters, thresholds, and history with you.
Gmail leans heavily on engagement. It is strict about anything that looks like bulk sending and comparatively generous toward mail that gets opened and answered. Microsoft weights domain and IP history more, which makes it unforgiving toward new domains and rewarding toward senders with a long consistent record. Corporate mail systems behave differently again, and a self-hosted gateway or a security appliance in front of a company's inbox will sometimes block whole IP ranges with no signal back to you at all.
So a message that reaches the inbox reliably at one provider can sit in spam at another, with identical copy, from the same domain, on the same day. If your entire sending capability runs through one route, you have no way to observe that and no way to route around it.
Use Separate Domains, Not Subdomains
This is the correction that matters most, and it is the most common mistake in otherwise sensible advice on this topic, including an earlier version of this article.
The usual recommendation is to send cold outreach from a subdomain: keep yourcompany.com for real business and send campaigns from connect.yourcompany.com. It feels like separation. It is not enough.
Subdomain reputation is not independent of the root domain. Receiving systems treat the organisational domain as a meaningful unit, and damage at a subdomain can and does affect how the root is judged. Which means a subdomain gives you the appearance of isolation while leaving the thing you were protecting still exposed. If the point of the exercise is that a burned outreach channel must not touch your customer email, a subdomain does not achieve it.
Separate registered domains do. Send cold outreach from domains that are not your primary brand domain and not children of it. Typically these are close variants, registered specifically for outreach, each with its own authentication and its own reputation to win or lose. When one is flagged, your main domain never hears about it.
There is a second benefit that only shows up at scale. Once outreach lives on domains that are genuinely expendable, you can retire a damaged one instead of nursing it back over eight weeks. Lidgen runs this layer across hundreds of sending domains for exactly that reason: no individual domain is precious, so no individual domain becoming a problem is a crisis. That is the difference between infrastructure and a single asset you are afraid to lose.
What Diversification Actually Covers
Four independent layers, in rough order of how much protection each buys you:
Domain separation. Business-critical mail and cold outreach on different registered domains. The single highest-value split, and the one most teams skip.
Provider diversification. Not every sending domain on the same provider. Providers have correlated failures, and their limits and tolerances differ enough that spreading across them genuinely reduces exposure.
IP separation. Different sending IPs for different purposes, so a shared-IP neighbour's behaviour is not your problem.
Mailbox distribution. Volume spread across multiple mailboxes per domain rather than concentrated in one. This helps with per-mailbox rate limits, though it does not spread reputation risk, since every mailbox on a domain draws on that domain's standing.
The layers are not interchangeable. Adding mailboxes to one domain raises your ceiling without reducing your risk. Adding domains reduces your risk. Know which problem you are solving.
A Tiered Structure That Works
Three tiers, with a hard wall between the first and the rest:
Tier 1, your primary domain, on your primary provider. Customer communication, internal mail, transactional email, anything a running business depends on. This domain never sends cold outreach. Not from a subdomain, not "just this once".
Tier 2, dedicated outreach domains. Separate registered domains, each fully authenticated, each warmed, each monitored on its own. This is where campaigns run, and where volume scales by adding domains rather than by pushing existing ones harder.
Tier 3, prepared reserve. Additional authenticated and warmed domains held ready. The point of a reserve is that it is already warm when you need it, because a domain you register the day a campaign dies is four to eight weeks from being useful.
Tier 3 is the one teams cut first and regret most. Warmup is the constraint that cannot be compressed by urgency, so reserve capacity has to be built before there is a reason to want it.
How Far Should You Take This?
Diversification has a cost, and the honest answer is that the right amount depends on the volume you need and what an outage would cost you.
If you are sending a modest volume and a two-week deliverability problem would be an inconvenience rather than a quarter-ending event, one primary domain plus two or three warmed outreach domains is a reasonable place to stop. That already gives you the critical separation and some redundancy.
If outbound is how your pipeline gets filled, the calculation changes. At real volume you need enough domains that each one stays comfortably inside safe daily thresholds, plus reserve, plus per-domain monitoring, plus warmup running continuously in the background. That is a standing operational function rather than a setup task, and it is the reason a lot of teams end up either under-diversified or spending a surprising share of someone's week on email plumbing.
The volume arithmetic behind this is worth understanding in its own right: how many cold emails you can safely send per day.
The Cost of Not Diversifying
When a single email system fails, the effects arrive together:
Outreach stops, and the pipeline gap appears one sales cycle later, when it is too late to fix
Customer communication degrades quietly, because nobody tells you their invoice went to spam
Domain reputation recovery runs weeks to months, and cannot be accelerated by paying more
Replacement infrastructure needs registering, authenticating, and warming before it carries load
The cost of redundancy is a handful of domains and the discipline to keep them warm. The cost of not having it is measured in quarters.
Getting There From One Domain
The order matters more than the speed. Work through it in sequence rather than in parallel:
Stop sending cold outreach from your primary domain, today. This is the only step that is urgent. Everything else can be built.
Register two or more separate outreach domains and configure SPF, DKIM, and DMARC correctly on each. Authentication errors are the most common reason a technically diversified setup still fails.
Warm each domain properly before it carries real volume. Four to eight weeks of gradual ramp, or pre-warmed infrastructure if you cannot afford to be idle for two months.
Verify placement per domain, not in aggregate. Send test traffic to Gmail, Microsoft, and a corporate-hosted address and check each separately. An average hides the one route that is broken.
Set thresholds and monitor per domain. Bounce rate under 3%, complaint rate under 0.1%, and reply-rate trend as the early warning. Aggregate campaign metrics will not show you a single failing domain until it has already cost you.
Build the reserve while nothing is wrong. Reserve capacity is only reserve if it is already warm.
FAQ
Can I use a subdomain of my main domain for cold outreach? You can, but it does not give you the protection people expect from it. Receiving systems associate subdomain behaviour with the organisational domain, so a flagged outreach subdomain can still affect how your primary domain is judged. Separate registered domains are what actually isolate the risk.
How many sending domains do I need? Enough that each one stays inside safe daily limits for the volume you need, plus reserve. For modest volume that is two or three. For a pipeline that depends on outbound it is considerably more, because the number is driven by your volume target divided by the safe per-domain rate, not by preference.
Does using multiple email providers actually help, or is it overkill? It helps, because providers fail and throttle independently and their tolerances differ. It is the second priority though. Domain separation buys you more protection per unit of effort, so do that first.
Do I need dedicated IPs? Only at sustained volume. A dedicated IP means your reputation is entirely your own, which is an advantage once you send enough to establish one and a disadvantage when you do not, because a low-volume dedicated IP has no history to trade on. Below that threshold, a well-managed shared pool is usually better.
If one of my outreach domains gets blacklisted, can I recover it? Often, over four to eight weeks of reduced volume and clean sending, sometimes not at all. The strategic answer is to design so that you do not need to: if a domain is genuinely expendable, retiring it and moving volume to a warm reserve is faster and cheaper than rehabilitation.
Should transactional email go on its own domain too? Ideally yes. Password resets and receipts have to arrive, and separating them from marketing mail means a promotional campaign cannot affect whether a customer can log in.
Need resilient sending infrastructure without making it someone's job? Lidgen operates pre-warmed, separated, per-domain-monitored infrastructure at scale, so a flagged domain is an operational event rather than your pipeline stopping. Book a demo.