Most teams that stand up cold email automation don't fail because the copy is bad. They fail because they flip the switch on domain infrastructure, prospect data, and sequencing logic that was never tested under load — and by the time reply rates crater or a domain gets flagged, the damage takes six to eight weeks to undo.
The pattern is consistent enough to predict: a team replaces manual SDR outreach with automated prospecting, sees a strong first ten days, then watches deliverability and reply rates collapse in week three or four. Almost every post-mortem traces back to the same handful of things that were never verified before launch, not to the platform itself.
This is the checklist we walk teams through before any automated sequence goes live. It's organized around the four systems that actually determine whether B2B outreach at scale works: sending infrastructure, prospect data, targeting logic, and monitoring. Run through all twelve before you turn volume on, not after reply rates tell you something's wrong.
1. Every sending domain is separate from your primary company domain. If your outbound domains share reputation with the domain your billing and support emails run on, one bad sequence can put transactional email in spam too. Confirm your cold email automation is routed through dedicated domains that redirect to your main site, not through the domain in your email signature.
2. Every mailbox has completed a minimum 21-day warmup with real engagement. A mailbox with zero sending history gets filtered by default — inbox providers treat it as unknown risk regardless of how good the copy is. Check the warmup log for each mailbox, not just the domain age. New mailboxes added to an established domain still need their own warmup curve.
3. SPF, DKIM, and DMARC are correctly configured and passing, not just present.
A record that exists but is misaligned (wrong DKIM selector, DMARC policy set to none with no alignment) provides none of the deliverability protection teams assume it does. Pull an actual test send through a header analyzer and confirm all three pass, rather than trusting that the records were set up once and are fine.
4. Mailbox-to-domain ratio matches your planned send volume, not your current one. Three to five mailboxes per domain is the safe ceiling for B2B cold outreach. If your rollout plan doubles volume in month two, the domain and mailbox count needs to be provisioned for that now — adding mailboxes reactively means every new one restarts its own warmup clock while the campaign is already running.
5. Every email address has passed syntax, MX, and SMTP-level verification within the last 30 days. Lists verified two months ago have already decayed — B2B contact data degrades at roughly 2-3% per month as people change roles. Re-verify before load, not after the first bounce report.
6. Catch-all domains are flagged and routed to a more conservative sending cadence. A catch-all domain accepts mail regardless of whether the mailbox exists, which means standard verification can't confirm deliverability the normal way. Sending to catch-all addresses at full volume with no adjustment is one of the most common causes of bounce-rate spikes that seem to come from nowhere.
7. Source and recency of every contact record is logged. If a prospect's title or company was scraped six months ago, that record needs a freshness flag, not blind trust. Automated prospecting pulling from a stale enrichment pass produces personalization that reads as wrong rather than irrelevant — a worse outcome than generic copy, because it signals the sender didn't check.
8. Your ICP scoring model has been tested against 20-30 known closed-won and closed-lost accounts. A scoring rubric that hasn't been validated against real outcomes is a guess dressed up as a framework. Run your model against last year's actual wins and losses before trusting it to gate who enters a sequence — if it would have scored your best-fit closed deals as low-priority, the weighting is wrong. We cover the four dimensions worth scoring on in our ICP scoring framework.
9. Disqualification rules are as explicit as qualification rules. Most ICP models define what a good fit looks like and leave "who doesn't get contacted" implicit. Explicit disqualifiers — company size floor, industry exclusions, existing customer suppression, recent-contact suppression — prevent wasted sends and the reputational cost of prospecting people who were never going to convert.
10. Personalization touches at least three structural points per email, not just the opening line. Spam filters and prospects both notice when only the greeting is customized and everything else is templated. Real personalization needs to show up in the opening hook, one specific detail in the body, and the call-to-action framing. Our deliverability tips for automated B2B teams goes deeper on why this matters more for automated sends than manual ones.
11. Bounce, complaint, and unsubscribe thresholds are set to auto-pause, not just alert. An alert that a human has to see and act on is a 12-24 hour lag in a system where domain damage can happen in an afternoon. Hard bounce rates above 5% and spam complaints above 0.3% should stop sending automatically, not wait for someone to check a dashboard.
12. Someone owns weekly review of sequence-level and domain-level metrics, not just monthly. Automated prospecting removes the person who used to notice a problem by feel — a rep who senses their reply rate dropped before the report confirms it. Replace that instinct with a scheduled review, even a 15-minute one, or problems compound for a full reporting cycle before anyone looks.
The teams we see stall six weeks in almost always skipped two or three of these, usually numbers 2, 5, and 11 — warmup, list freshness, and auto-pause thresholds. None of those show up as a problem in week one. They show up in week four, after enough volume has passed through unverified infrastructure to do real damage, and by then the fix costs 60-90 days of reduced sending to recover domain reputation rather than the few hours it would have taken to check beforehand.
None of these twelve checks require sophisticated tooling — a spreadsheet and 90 minutes covers most of them for a first launch. What they require is treating cold email automation as infrastructure that gets audited before it runs, the same way you'd check a CI pipeline before merging to production, rather than a tool you configure once and trust indefinitely. Teams that build this checklist into every new domain and every new sequence launch consistently avoid the stall pattern that takes down teams that don't.
If you're evaluating whether to replace SDR headcount with automated prospecting, this checklist is also a reasonable way to pressure-test a platform before you commit — ask any vendor how they handle warmup pacing, catch-all detection, and auto-pause thresholds, and the answer tells you more than a demo will. We've written about the full cost and headcount math of SDR replacement if you're still building the business case.
OnyxSend runs domain rotation, warmup pacing, pre-send verification, and auto-pause thresholds as defaults rather than settings someone has to remember to configure. If you want this checklist handled at the infrastructure level instead of manually, see pricing or request access to run it against your current sending setup.