This guide assumes lead email verification is already deployed and passing. It covers what breaks at scale and how mature teams operate it.
Edge cases that break a working setup#
- Trusting a vendor's 'verified' label from months ago.
- Treating catch-all as valid.
- Mail forwarded through mailing lists or personal forwarders, which alters headers and content.
- Acquisitions and rebrands that introduce domains nobody audited.
- Vendors silently changing their sending infrastructure.
Operating it as infrastructure#
- Assign an owner for each sending domain and each vendor relationship.
- Put DNS records under version control or a change-review process.
- Alert on authentication pass rate drops and reputation changes, not just outages.
- Run a quarterly audit against the setup steps below.
- Document runbooks for the three most common failures.
Reference: the baseline setup#
- Verify every address through an API before it enters a sequence.
- Segregate catch-all domains and send to them at lower volume.
- Refresh verification for any lead older than 90 days.
- Enrich with 3 to 5 data points that drive the opening line.
Frequently asked questions#
What bounce rate is safe for cold email?
Under 2 percent. Above 5 percent, pause and re-verify the list before continuing.