emailmarketing.net

Sending Infrastructure Practices

Dedicated vs. shared IPs, subdomain strategy, domain warm-up, From-address hygiene, feedback-loop wiring, reputation monitoring tools, and a troubleshooting framework.

Operational9 min read

Who it is for ESP operators, Senders

Applies to senders on any platform

Before you size a fleet of IP addresses, you have to decide whether you need a dedicated IP at all, how to build the reputation of your domains, and how to monitor both. ESP guides from Postmark, AWS SES and Twilio SendGrid agree on most of the answers, collected below. For sizing and segmenting IP fleets, see Basic IP Allocation.

Dedicated vs. shared IPs

Basic IP Allocation explains how to size dedicated-IP fleets. The question that comes first is whether to use a dedicated IP at all.

Aspect Dedicated IP Shared IP
Impact of other senders None: the reputation is entirely yours Other senders in the pool can raise or damage your standing
Volume requirement High, sustained volume is mandatory Any volume
Warm-up Required, over weeks to months None; send immediately
Cost Premium Lower
Reputation management Yours to manage Managed by the provider
Tolerance for errors Low: every mistake lands on your reputation Higher: the volume of the pool absorbs errors

Dedicated-IP volume floors

"How much volume justifies a dedicated IP?" has no single answer, because the published numbers measure different things. The floors and vendor minimums below span roughly 5–10x, but they do not contradict each other: they answer different questions. The two floors below are the reference figures; other guidance on dedicated IP addresses refers to them.

Floor Number What it measures
Floor for isolating transactional mail ~1,000 messages/day The low-end volume at which isolating transactional mail on its own dedicated IP stays readable to receivers (GreenArrow, Advanced IP Segmentation). Transactional mail is isolated because it is highly relevant, even below the general statistical floor.
General statistical floor for each IP 40,000 messages/week (~5,700/day) The minimum sustained volume that any IP needs for mailbox providers to gather statistically significant data on engagement and complaints (GreenArrow, Basic IP Allocation). Below this, an IP does not send enough for its reputation to stabilize.

Vendor thresholds for dedicated IP addresses (house rules). ESPs publish their own minimums. These reflect each vendor's product tiers and support costs as much as receiver statistics. Depending on the vendor's model, they sit above or below the two floors, and they do not contradict each other:

Vendor Threshold Framing
AWS SES "a few hundred per day" to allocate the first dedicated IP; below that, customers are steered to shared IPs The lowest bar. SES automatically moves low-volume dedicated IPs back to the shared pool (see Multi-Tenant Architecture)
Twilio SendGrid ~50,000/month (~1,650/day) recommended Below this, a well-managed shared pool is advised
Mailgun ≥ 100,000/month (~3,300/day) recommended See Reputation Incident Recovery
Postmark ~300,000/month (~10,000/day) to properly maintain a dedicated IP The highest bar

In short, a dedicated IP for transactional mail can be justified at ~1,000/day. Any IP that carries a general or bulk stream needs ~40,000/week before receivers can read its reputation statistically. The vendor minimums are commercial house rules on top of both.

Postmark adds caveats. A dedicated IP is not a silver bullet: for senders below the volume bar it can hurt deliverability, and "a dedicated IP is a way for ESPs to lower their support overhead" as much as it is a delivery feature. Dedicated IPs also demand consistent, predictable volume, and sudden spikes are flagged as suspicious. Modern filtering gives domain reputation more and more weight compared with IP reputation.

Domain reputation and subdomain strategy

Domain reputation is the opinion that receivers (mailbox providers and anti-spam services) hold of your domain. Unlike IP reputation, it is portable. It follows the domain across sending systems and providers, so a domain with a history of spam carries that history to any new infrastructure. Poor domain reputation can drag down even transactional mail (Postmark).

IP reputation and domain reputation are evaluated separately, but they interact: a poor IP reputation can harm a domain that sends through that IP, even when the domain's own record is good.

Subdomain separation

Both AWS SES and Postmark recommend separating mail streams by subdomain. This is the domain-level counterpart of separating IP addresses by reputation, as described in Advanced IP Segmentation:

  • Send marketing from a subdomain such as marketing.example.com and transactional mail from orders.example.com, rather than everything from example.com (AWS SES).
  • Subdomains develop independent reputations (for example, notify.example.com and newsletter.example.com), so a marketing incident, such as a spam-trap hit or a content filter trigger, does not take down transactional delivery. They affect each other only indirectly (Postmark).
  • Monitor cousin domains (for example, company.com and company-mail.com). Their reputations and any abuse of them can affect how mail from your brand is judged (SendGrid).

The four domains in every message (Postmark)

  1. DKIM signing domain (d=): sign with your own domain, not a vendor default, so the reputation builds up for you.
  2. Return-Path domain: use a custom Return-Path (CNAME) that matches or aligns with your From domain. It is required for SPF alignment under DMARC.
  3. Domain of the From and Reply addresses: it should clearly identify the brand. Publish a DMARC policy on it.
  4. Domains in the URLs in the content: third-party links harm delivery only when the linked domains are observed doing something deceptive or malicious. Still, link only to trusted sites you control (SendGrid).

From-address hygiene (AWS SES)

  • Some ISPs attach reputation to the From address itself, and it is also the recipient's first impression.
  • Never send bulk mail from an address at a mailbox provider (for example, sender@hotmail.com). Large volumes from a consumer mailbox address are treated with suspicion. Send from a domain you own.
  • Avoid no-reply@ addresses as the From or Reply-To address. They signal that you do not want feedback from recipients, and replies are a positive engagement signal.
  • Keep the domain's WHOIS record accurate. An honest, current record signals legitimacy.

Domain warm-up

New domains and subdomains need warm-up just as new IP addresses do (see IP Warm-Up), and the domain keeps its history for longer. Postmark's schedule gives volumes for each receiving provider, for example for each of Gmail, Yahoo and Microsoft:

Period Daily volume per provider
Days 1–2 50–100
Days 3–4 200 (if metrics healthy)
Days 5–7 400
Days 8–10 600–800
Days 11–14 1,000–1,500
Days 15–17 2,000–3,000
Days 18–21 4,000–5,000
Days 22–25 7,500–10,000
Days 26–30 Full intended volume

Pace the growth by roughly doubling volume each day at the start. At substantial volumes, slow to daily increases of 20–50% (30–50% a day in weeks 2–3, then 20–30% a day). Expect an established reputation and dependable delivery at full volume in 3–6 weeks. No single schedule fits the thresholds of every provider.

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) gives a different figure. Its Sender Best Common Practices (Version 4.0, August 2026, section 2.5) suggests treating 6 weeks as an average domain warm-up, which sits at the top of the range above. The two figures answer slightly different questions: the range above is when Postmark expects dependable delivery at full volume, and M3AAWG's figure is a typical length for the whole warm-up. M3AAWG adds these points:

  • Warm a new subdomain too, to be safe, even when the organizational domain already has an established reputation. A domain with no sending history is treated with the same caution as a domain with a bad one.
  • Spread each day's messages over the day instead of sending the batch at once, and send campaigns on a regular schedule until the domain is warm.
  • Watch SMTP logs for deferrals and bounces, and slow down if deferrals spike. Watch for spikes in unsubscribes and complaints. A large spike in opens or clicks may mean security appliances are scanning your mail, and a drop may mean it is going to the junk folder.
  • M3AAWG does not recommend artificial warming, and warns that it may be against the law.

During warm-up, start with your best-engaged recipients and widen the audience in tiers (compare the rule of sending to the best-engaged first in IP Warm-Up):

Days Audience
1–4 Most engaged (previously opened and clicked)
5–7 Opened within last 60 days
8–10 Opened within last 90 days
11–14 Engaged within 120 days
15+ Progressively less recent engagement; re-engagement campaigns last

The most important rule: never increase volume before you review the engagement and bounce metrics of the previous send for each provider. If metrics degrade, cut volume by 25–30% until they return to normal. Metrics and Benchmarks lists the specific triggers for corrective action. It is better to take an extra week or two than to rush and damage long-term deliverability.

Feedback loops and notification wiring

A feedback loop (FBL) is a channel through which a mailbox provider reports recipients' spam complaints back to the sender. It has these operational requirements:

  • Register for the FBLs of the providers you send to (only some offer them). Word to the Wise maintains a reference list of where to sign up for each ISP's FBL (Postmark). ESP platforms typically set these up in advance and forward complaints automatically, as AWS SES does.
  • Complaint notifications redact the address of the person who complained. Embed traceable X-headers or identifiers in the body so you can map each complaint to an address and a campaign (AWS SES).
  • The mailbox that receives bounce and complaint notifications must reliably accept mail and must not filter the notifications as spam (AWS SES). See List Hygiene for what to do with the data.
  • Gmail provides complaint data through Postmaster Tools rather than through an FBL that reports each message. Tag campaigns with unique Feedback Loop identifiers to see complaint rates broken down by campaign or sender, and to isolate problem content quickly (SendGrid).

Reputation monitoring tools

Tool What it gives a sender
Google Postmaster Tools Domain and IP reputation at Gmail, rated Bad / Low / Medium(Fair) / High (Bad means mail is almost always rejected or sent to spam; High means it is rarely filtered); a spam rate dashboard (monitor it daily); FBL identifier data
Microsoft (Outlook.com) postmaster tools and SNDS Reputation and complaint data for Microsoft properties
Yahoo postmaster Delivery and complaint data at Yahoo
Senderscore.org Proprietary 0–100 score of overall IP performance
Cisco Talos Intelligence Reputation of IP addresses and domains, rated Good / Neutral / Poor, with volume history
MXToolbox Blocklist status checks for IP addresses and domains, plus health checks for DNS and domains; SendGrid calls it "the best free lookup option"

Also verify that reverse DNS (PTR) records exist and match for every sending IP, which is a bulk-sender requirement at Google and Yahoo (SendGrid). Validate authentication (SPF, DKIM and DMARC) with public checkers.

Blocklists (denylists)

  • Providers and anti-spam services list IP addresses and domains that show many spam-trap hits, high complaint volumes, or both (SendGrid).
  • The impact varies widely. Some lists strongly influence major providers; many are noise.
  • If you are listed on a major blocklist, stop sending immediately, complete the delisting procedure, then resume at significantly reduced volume (Postmark).
  • Beware of pay-to-play lists that charge for delisting rather than assessing sender behavior (SendGrid).

Troubleshooting framework (Postmark)

When placement or delivery drops, diagnose these five areas in order:

  1. Authentication: verify SPF, DKIM, alignment of the custom Return-Path, and DMARC with public validators.
  2. Content: score the message with a checker based on SpamAssassin, and run seed tests. If a template change preceded the drop, revert the changes one at a time (see the content rules in Metrics and Benchmarks).
  3. Engagement: audit bounce, complaint and open rates against the thresholds; suppress hard bounces; avoid noreply@.
  4. Reputation: check domain and IP reputation in the postmaster tools and blocklist lookups above.
  5. Infrastructure: confirm rDNS (PTR) records, FBL registrations and the health of the IP pool, and check that the sending software signs with DKIM correctly.

There is no silver bullet. Deliverability means ongoing monitoring across all five areas, built on clean lists and strong engagement.

Check your own record

The free check reads what your domain publishes in DNS.

In this topic

All 18 in Operations →