You sent forty pitches and got nothing. Not a no, not a "wrong fit", nothing. The instinct is to blame the writing and start again with a better hook. That is usually the wrong repair, because a meaningful share of those emails were never seen by a person. They were sorted into spam, or into Gmail's Promotions tab, or rejected at the gateway before the host's inbox ever heard about them.
Deliverability is the least glamorous part of outreach and the one that quietly decides whether any of the rest matters.
First, find out whether it is a delivery problem
Before rewriting anything, get evidence.
Send a test to a Gmail address, an Outlook address and one address on a small business domain, all of which you control and none of which have ever corresponded with your sending account. Look at where each one lands. If any of the three goes to spam or to Promotions, the pitch was never the problem.
Then open the received message and look at the raw headers. In Gmail that is the three-dot menu, then "Show original". You are looking for three lines:
| Header | What you want to see | What it means |
|---|---|---|
spf |
PASS |
This server was allowed to send for your domain |
dkim |
PASS |
The message was signed and arrived unmodified |
dmarc |
PASS |
The two above line up with the address the reader sees |
Two passes and a fail is a fail. Providers weigh all three together, and a DMARC failure in particular is now treated as a strong negative signal.
What the three records actually do
They get explained badly, usually with a passport metaphor that leaves you no better off. Concretely:
SPF is a list, published in your DNS, of the servers allowed to send mail for your domain. When mail arrives claiming to be from you, the receiving server fetches that list and checks whether the sending server is on it. If you send through Google Workspace, Microsoft 365 and a sequencing tool, all three need to be in that one record. A common failure is having two separate SPF records; that is invalid, and the check fails rather than merging them.
DKIM is a cryptographic signature. Your sending server signs each message with a private key; the receiving server fetches your public key from DNS and verifies the signature. It proves the message genuinely came from you and that nobody altered it in transit. Each sending service has its own key and its own record, so connecting a new mailbox means adding another one.
DMARC ties the other two to the address the reader actually sees. Without it, SPF and DKIM can pass for a domain in the technical envelope while the visible "From" says something else entirely, which is exactly how spoofing works. DMARC also tells receivers what to do when the checks fail, and asks them to send you reports.
Since February 2024, Gmail and Outlook both require a DMARC record from anyone sending in bulk. A record at
p=nonecosts nothing, changes no behaviour, and satisfies the requirement.
Start at p=none, read the reports for a few weeks, and only move to quarantine and then reject once you can see that everything legitimate is passing.
Set it up in this order
Order matters, because each step depends on the one before it.
- Pick a sending subdomain. Something like
mail.yourcompany.comoroutreach.yourcompany.com. Reputation attaches to the sending domain, so this keeps a rough campaign from touching the mail your customers and your accountant rely on. - Publish SPF for that subdomain, listing every service that will send from it. One record, not several.
- Enable DKIM in each sending service and publish the key each one gives you.
- Publish DMARC at
p=nonewith a reporting address you will actually read. - Wait for propagation, then verify with a real test send and read the headers as above.
- Warm the domain before any real campaign.
Skipping step six is the most common expensive mistake. A domain with no sending history that suddenly emits forty cold emails in a morning looks exactly like a compromised account, and providers treat it accordingly.
Warming, and the volume ceiling
Warm-up is unglamorous and takes about three weeks. Begin with a handful of sends per day to addresses that will open and reply, and increase gradually. Genuine two-way conversation is what builds reputation; blasting a list of contacts who never respond builds the opposite.
Once warmed, hold to a ceiling. For cold outreach, under forty sends per mailbox per day is a sensible cap, and staying well under it is safer than sitting on the line. If you need more volume, add mailboxes rather than raising the ceiling on one. Spreading a campaign across several warmed mailboxes is both safer and more resilient: one account developing a problem does not stop the campaign.
Two numbers to watch, both of which should stay very low. A rising bounce rate means your list quality has dropped and you should stop and clean it. A rising complaint rate, people marking you as spam, is the more serious of the two and warrants stopping the campaign entirely.
The content side, which matters less than you think
Once authentication and volume are right, a few writing habits still help.
Send genuine plain text rather than HTML dressed up to look plain. Tracking pixels, heavy link wrapping and image-only bodies all move a message toward the promotional bucket. Keep links to one or two. Avoid the subject-line register that reads like a campaign; a real person writing to a real person does not use an exclamation mark or the phrase "quick question about your podcast".
And personalise for real. Beyond the deliverability arithmetic, a message that is obviously written for this show is the one that gets a reply, which is the strongest positive signal you can send a mailbox provider. The structure of a pitch that earns that reply is a subject of its own, and it depends on having done the research on the show first.
When to stop tuning and start sending
Deliverability rewards getting the setup right once and then leaving it alone. Authenticate the subdomain, warm it properly, stay under the ceiling, watch bounces and complaints, and spend the rest of your attention on the pitch and the list.
Encored checks SPF, DKIM and DMARC on every sending domain you connect and shows exactly what is missing, runs a pre-flight review of sender setup and account health before a sequence launches, holds a per-mailbox daily cap so volume stays inside what each account can handle, and pauses a sending account automatically when bounces or complaints start to climb. See how the workspace handles sender health, or start free for seven days and connect a mailbox to see where yours currently stands.
Common questions
- Why do my podcast pitches go to spam?
- Almost always authentication, volume, or reputation. Check SPF, DKIM and DMARC first, then your daily send rate, then whether your domain has any sending history at all. Content is the last thing to blame, not the first.
- Do I need a separate domain for cold outreach?
- A separate sending subdomain, yes. It isolates reputation, so a bad campaign cannot damage the deliverability of your normal company mail. Buying a whole lookalike domain is a heavier move and usually unnecessary for podcast outreach.
- How long does domain warm-up take?
- Three weeks is a realistic floor for a brand new sending domain. Start at a handful of sends a day and roughly double every few days, keeping replies and engagement high, until you reach your target volume.
- Is DMARC really required?
- Since 2024, Gmail and Outlook require a DMARC record for anyone sending in bulk to their users. A record at p=none satisfies the requirement and starts your reporting, so there is no reason to be without one.