Skip to content
AgentSDR
Star

Guide · 11 min read

Cold email from Google Workspace

A practical guide to sending outbound email from Workspace mailboxes: how to set them up, how much to send, what to authenticate, and how to keep a list clean.

· By the AgentSDR team

The short version

Cold email works when a real person at a real company receives a relevant, low-volume message from a mailbox that mail providers trust. It fails when a domain sends too much, too fast, to a list nobody checked. Almost every piece of advice in this guide comes down to one idea: protect the reputation of the domain and mailboxes you send from, because they are slow to build and quick to damage.

Google Workspace is a good place to send from. You get real Gmail mailboxes, your own domain, admin controls and a sending infrastructure with a long track record. It does not make you immune to spam filtering. The same filters that judge any sender judge you, and they care about authentication, complaint rates, bounce rates and how your sending pattern looks over time.

This guide covers general practice first and then, at the end, how AgentSDR’s email sequencesput it into defaults. Where we cite a provider rule, we link to the provider’s own documentation. Where we describe common practice, we say so; nobody outside the providers publishes exact thresholds, and they change.

Domains and mailboxes

Which domain to send from

Sending cold email from your primary company domain puts that domain’s reputation at risk. If complaints pile up, the mail your team sends to customers can start landing in spam too. To avoid that, many outbound teams buy one or more secondary domains, close to the brand name, and send prospecting mail from those. The website on the secondary domain simply redirects to the main site.

The cost is a cold start. A brand new domain has no sending history, so it needs a slow ramp (covered below). A domain that is a few months old and has sent small, well-received volumes is worth more than a fresh one. There is no universal right answer: a founder emailing 20 hand-picked prospects a day from their own address has a very different risk from a team emailing thousands a week.

How many mailboxes

Volume per mailbox should stay modest, so volume overall comes from having more mailboxes rather than pushing each one harder. Two or three mailboxes per sending domain, each with a real display name and a plausible role, is a common pattern. Each mailbox should be a genuine Workspace user with a profile picture and a signature, and ideally one that also sends and receives ordinary email.

SPF, DKIM and DMARC

These three DNS records tell receiving servers that your domain authorised the mail they are looking at. Set them up before the first send, not after the first bounce.

  • SPFlists the servers allowed to send mail for your domain. For Google Workspace, the record includes Google’s servers. You publish one SPF record per domain, as a TXT record.
  • DKIM signs each message with a key so the receiver can check it was not altered and really came from your domain. You generate the key in the Google Admin console and publish its public half as a DNS record, then turn signing on.
  • DMARC tells receivers what to do when SPF or DKIM fail for your domain, and where to send reports. A sensible start is a monitoring policy that reports without rejecting, tightened once the reports look clean.

Google’s sender guidelines make this concrete. From February 2024 every sender to Gmail must set up SPF or DKIM, keep spam rates reported in Postmaster Tools below 0.3%, and meet basic technical requirements such as TLS and valid forward and reverse DNS. Senders of 5,000 or more messages a day to Gmail addresses must also set up SPF, DKIM and DMARC, align the From domain with SPF or DKIM, and support one-click unsubscribe for marketing and subscribed mail. The full text is in Google’s email sender guidelines.

A cold-email programme should sit well below 5,000 messages a day, but that is no reason to skip DMARC. Treat the bulk-sender list as the standard to meet, not the line to stay under. Check your setup with a test message to a Gmail address and look at Show original: it reports SPF, DKIM and DMARC as pass or fail.

Daily volume and gaps

Google documents a hard ceiling for paid Workspace accounts of 2,000 messages a day per user, with lower caps for mail merge and trial accounts (see Gmail sending limits in Google Workspace). Hit a limit and the user cannot send for up to 24 hours. That ceiling is about abuse prevention. It says nothing about what is safe for cold email, where filters judge the pattern, not the count.

There is no published safe number. Common practice among careful senders is a few dozen cold emails a day per mailbox once it is established, and far fewer for a new one. AgentSDR’s own guidance is that deliverability usually drops above about 50 a day from one Workspace mailbox. Treat figures like these as conservative starting points and adjust to your own bounce and reply data.

Randomise the gap between sends

A human does not send an email every exactly 60 seconds. Sending in bursts, or on a fixed timer, is one of the clearest automation signatures. The better pattern is a random wait between emails from the same mailbox, measured in minutes, inside the recipient’s working hours. If a mailbox sends 30 emails with 18 to 24 minutes between them, that is a bit over nine hours of spread-out activity.

Send inside working hours

Mail that arrives at 3 a.m. looks automated and gets read later, if at all. Pick sending hours in the time zone of the mailbox, weekdays only unless your market differs, and let anything that comes due outside the window wait for the next open slot.

Typical safe-side pacing for cold email
SettingCareful starting pointWhy
Emails per day, new mailboxA handful, rising over weeksNo history to judge you by yet
Emails per day, established mailboxA few dozen at mostKeeps complaint and bounce counts small
Gap between emailsRandom, in minutesAvoids a fixed-interval pattern
Sending windowWeekday working hoursMatches how real people send and read

This table is general practice, not a provider rule. Use it to pick a cautious start, then let your own results decide.

Warm sending patterns

A new mailbox on a new domain is an unknown. Receiving servers have no history to trust, so the first weeks set your reputation. The pattern that tends to work is gradual:

  1. Use the mailbox for ordinary email first: real conversations with colleagues and friendly contacts who will reply.
  2. Begin outbound with a tiny daily count, to the most relevant prospects on your list, with the best-targeted copy.
  3. Raise the daily count in small steps, only while bounces stay low and replies keep arriving.
  4. Stop raising it when results flatten. More mailboxes beat a bigger number on one.

Be sceptical of anything that promises to “warm up” a mailbox by exchanging automated mail with a network of other accounts. Artificial engagement is exactly the sort of pattern providers look for, and it teaches you nothing about how real prospects respond. Real replies from real recipients are the signal that matters.

Warm sending also means steady sending. A mailbox that sends 30 a day for a week, goes quiet, and then sends 150 in an afternoon looks irregular. Keep volume smooth, and pause rather than spike when you are not ready.

Copy and list hygiene

Start with a list worth sending to

The biggest lever on deliverability is not a setting, it is who you email. Every invalid address bounces, and a high bounce rate is a strong sign of a purchased or stale list. Before you send:

  • Verify addresses, especially anything older than a few months or bought in bulk.
  • Remove role addresses such as info@ and sales@ unless you have a reason to write to them.
  • Deduplicate, so one person never receives the same step twice.
  • Exclude existing customers, open opportunities and anyone who has asked not to be contacted.

Write like one person to one person

Plain-text style messages, short and specific, tend to outperform formatted newsletters in cold outreach. Avoid heavy images, many links and tracking-heavy layouts. Personalise the opening with something true about the prospect and avoid identical copy across a whole list: varying phrasing means no two emails are byte-for-byte the same.

Merge fields are the usual way to personalise at volume, and they carry one trap: an empty field produces awkward text such as “Hi ,”. Preview a few real leads before launch, including ones with missing data.

Follow-ups

Most replies to a cold sequence come after a follow-up, so a short sequence with sensible waits, typically a few days apart, is standard. Keep follow-ups in the same thread as the first email so they read as a continuing conversation, and stop the moment someone replies, whichever channel they use.

Bounces and unsubscribes

Two categories of failure need different handling. A hard bounce means the address does not exist or refuses mail permanently. Suppress it at once and never send to it again. A soft bounce or delay notice means delivery was postponed, for example by a full inbox. Retrying later can succeed, so these should not suppress anyone on the first notice.

Unsubscribes should be easy and honoured everywhere. Include a clear unsubscribe link in the body and the List-Unsubscribeheaders that let Gmail and Outlook show their own unsubscribe button. For marketing and subscribed mail, Google’s bulk-sender rules require one-click unsubscribe, and it is a good habit for cold email at any volume because an unsubscribe is far better for you than a spam report. Spam complaints, not unsubscribes, are what push the rate Google measures towards its 0.3% threshold.

Keep one suppression list for the whole organization, not one per campaign. Someone who opted out of your Q3 campaign should not be in your Q4 import.

Rules to follow

Cold email is regulated differently by country. In the United States, CAN-SPAM requires truthful sender identification, a working opt-out, a physical address and prompt honouring of opt-outs. The European Union and United Kingdom apply GDPR and ePrivacy rules (PECR in the UK), which in many cases require a lawful basis and prior consent to email individuals. Canada’s CASL generally requires consent for commercial email. Rules for business addresses differ from those for personal ones in some places. This is not legal advice: ask a lawyer who knows the countries you sell into. AgentSDR’s responsible use page covers the same ground.

How AgentSDR implements it

AgentSDR’s email sequences send through Google Workspace mailboxes you connect with a service account (domain-wide delegation). Each rule below is a default in the product, and the numbers are the organization’s Sending rules.

AgentSDR email defaults
BehaviourDefaultWhere it is set
Emails per day, per mailbox30 (allowed 1 to 200; warns above 50)Settings, Email, Sending rules
Gap between emails, one mailboxRandom 18 to 24 minutes (warns below 10)Sending rules
Sending hours, new mailboxesMonday to Friday, 09:00 to 18:00, time zone Asia/Kolkata unless you change itSending rules, then per mailbox
Follow-up wait3 days by default, minimum 1Sequence editor

A mailbox’s daily limit is copied from the organization rule when the mailbox is added, and its sending hours can be edited mailbox by mailbox. The default time zone is Asia/Kolkata, so change it in Sending rules if you sell elsewhere.

How sending runs

  • Connected mailboxes form one pool. New leads are shared across mailboxes in turn, and a lead then stays with the mailbox that sent its first email, so follow-ups come from the same address.
  • A queue is built once a day for each mailbox: due follow-ups first, most overdue first, then new leads, up to the daily limit.
  • About once a minute, each mailbox with queued leads sends one email, if it is past its random gap and inside its sending hours.
  • A follow-up with a blank subject goes out as a reply in the same thread, with Re: added to the earlier subject.
  • Merge fields come from any column in your CSV or XLSX, {A|B|C} spin text varies the copy, and Preview renders a step for a real lead and mailbox.

What stops a lead

  • A reply on any channel marks the lead Replied and removes their queued emails. Reply detection needs the optional Gmail Pub/Sub topic on the Google Workspace connection.
  • AgentSDR reads delivery failure reports in your mailbox, marks the lead Bounced and suppresses the address. A temporary delay notice does not suppress anyone.
  • Every email carries an unsubscribe link and a one-click unsubscribe header. Either way the address is suppressed and the lead becomes Suppressed.
  • Do Not Contact anywhere in your workspace is checked again right before each send. A suppressed address is never mailed again from any campaign in your organization.
  • Each step is sent at most once per lead. A failed send is marked Failed rather than retried automatically.

Replies, whatever the channel, land in one AI inbox with a classification and a drafted answer, so stopping a sequence and answering a lead are the same action.

Launch checklist

  1. The sending domain has SPF, DKIM and DMARC, and a test message to Gmail shows all three passing.
  2. The domain is registered in Google Postmaster Tools.
  3. Each mailbox is a real Workspace user with a name, photo and signature.
  4. New mailboxes start at low daily counts, and you have a plan to raise them in steps.
  5. Sending hours and time zone match your prospects, with randomised gaps.
  6. The list is verified, deduplicated and cleared against your customers and opt-outs.
  7. Every step is previewed on several leads, including ones with missing fields.
  8. Unsubscribe works, bounces suppress, and replies stop the sequence.
  9. You know the rules for the countries you are emailing.

FAQ

Questions, answered

How many cold emails can I send a day from Google Workspace?

Google documents an overall ceiling of 2,000 messages a day per paid Workspace user, but that is a platform limit, not a safe cold-email volume. Deliverability usually suffers long before it. AgentSDR defaults to 30 a day per mailbox and warns above about 50.

Do I need SPF, DKIM and DMARC for cold email?

Yes. Google requires SPF or DKIM for every sender to Gmail, and SPF, DKIM and DMARC for senders of 5,000 or more messages a day. Even below that threshold, all three are the baseline that receiving servers expect from a legitimate domain.

Should I send cold email from my main company domain?

Many teams use a separate, similar-looking domain so a deliverability problem cannot touch the mail their staff and customers rely on. It is a trade-off: a new domain has no reputation and needs a careful, slow start. Whichever you choose, authenticate it and keep volumes low.

How long should I wait between cold emails from one mailbox?

Spread sends out and randomise the gap rather than sending in bursts. AgentSDR waits a random 18 to 24 minutes between emails from the same mailbox by default and warns below 10 minutes.

What happens when someone unsubscribes or an address bounces?

The address should be suppressed so it is never mailed again. In AgentSDR, unsubscribes and hard bounces add the address to a suppression list that applies to every campaign in your organization, and a temporary delay notice does not suppress anyone.

Does AgentSDR set up SPF, DKIM and DMARC for me?

No. Those are DNS records on your domain, set up with your DNS host and Google Workspace admin. AgentSDR sends through your Workspace mailboxes, so they use whatever authentication your domain has.

Send like a careful human, at scale.

AgentSDR is open source and runs on your own Google Workspace mailboxes. Self-host it and keep the safe defaults.