New IP warmup: a realistic eight-week plan
A new IP has no past. Filters judge a sender by what it did before, not by what it wrote in its headers. That is why warming up a new IP is not a formality but building a history from scratch: several weeks of predictable sending, during which the big mail servers learn what to expect from you. Without it, the first campaign to a hundred thousand addresses ends in deferrals. Or a block.
Why warm up a new IP at all
Sender reputation is a set of observations, not a grade handed out in advance. The receiving server looks at volume, sending regularity, complaint counts, hard bounces and spam trap hits. Each of those signals means little on its own. Together they form a profile that decides whether you land in the inbox, the promotions folder or spam.
Reputation today has two layers: the IP address and the sending domain. You warm up both at once. The IP is infrastructure, the domain is identity - and the domain stays with you even when you change providers. In our fleet of sending servers we treat them as two separate counters that have to grow in parallel.
It is worth knowing what warmup does not do. It does not bypass filters - no process can, and nobody honest will promise it. It does not fix a list built from purchased addresses. It does not rescue content sent without the recipient’s consent. Warming up only works on clean material.
Why eight weeks and not two? Because the big filters judge trends in multi-day windows. One good day changes nothing. What counts is the curve: rising volume with stable engagement and low complaints. You can force a shorter cycle, I have done it myself under deadline pressure - but that leaves far less room to react when something goes wrong.
What you need ready before the first send
Set up authentication before you start, not along the way. DNS changes in the middle of a warmup reset part of the trust you have built.
- SPF - a correct
includefor the whole sending fleet, within the DNS lookup limit. Going over it ends in a permerror, which means no SPF at all. - DKIM - your own selector, a 2048-bit key, a signature on a domain aligned with the address in the From field.
- DMARC - start at
p=nonewith aruaaddress. You tighten the policy only once the reports confirm that all legitimate traffic passes. - Return-Path - envelope from on a technical subdomain. It aligns SPF and gives you a clean bounce channel.
- PTR - a reverse record for the IP pointing to a hostname that resolves back to the same IP.
- Sending subdomain - a separate one for marketing, kept apart from company mail and transactional mail.
- Unsubscribe and identification - an unsubscribe page, the sender’s physical address, a working List-Unsubscribe header with the One-Click variant.
Recipient consent is a condition for starting, not a box to tick later. The GDPR and article 398 of the Polish Electronic Communications Law require it for B2B sending too. A company address does not excuse you from asking for consent. There is no point pretending otherwise.
Tip: before you start on the list, send tests to your own mailboxes at a few large providers and read the full headers. What you care about is the SPF, DKIM and DMARC result, and whether the Return-Path matches the technical subdomain. Five minutes of checking saves a week of rebuilding.
List segmentation: who goes in the first wave
A warmup is built on your most active recipients. They are the ones who open, click and do not report spam, so they give filters exactly the signal you need at the start. The full base comes later. If at all.
Split the list into cohorts by last activity. First the people who opened or clicked in recent weeks. Then recipients from the last quarter. Then older layers, colder and colder. Addresses inactive for a year or more stay outside the warmup until the very end - and often they are not worth going back to at all.
- Cohort 1 - a click within the last 30 days. They go in during week one.
- Cohort 2 - an open within the last 90 days. They go in once bounces and complaints from cohort 1 are stable.
- Cohort 3 - activity in the last six months. They join mid-cycle.
- Cohort 4 - subscribed, but no activity for up to 12 months. The final weeks, in small batches.
- Outside the cycle - no response for over a year. A separate re-engagement campaign after the warmup ends, or removal.
Clean the base before you start. Typos in domains, role addresses like info@ or office@, records with no MX - those are hard bounces waiting to happen. Segmenting and cleaning the list goes faster when the tool supports it - email marketing platform features let you build cohorts from real recipient activity. And purchased lists or ones scraped from websites disqualify the whole process: spam traps hit immediately, and no schedule change will undo the reputation built on them.
The eight-week plan, week by week
There is one overriding rule: volume grows gradually, cadence stays the same. Jumping from a thousand to twenty thousand in a single day does more harm than moving slower than planned.
- Weeks 1-2 - your most active recipients only, low daily volume, the same sending time. You watch server responses, not sales results.
- Weeks 3-4 - you double the daily volume and at the same time widen the cohort by another activity layer.
- Weeks 5-6 - you move into less active segments and send the first full campaigns instead of test batches.
- Weeks 7-8 - you reach your target volume and settle the rhythm. The goal is repeatability, not a record.
Split large sends by provider. Every filter counts differently, so a separate pace for the biggest receiving domains gives you control: when one starts deferring, the rest carries on unchanged. And send on the same days, at the same hours. Predictability is a signal in itself - the receiving server recognises a pattern faster than it reads content.
You stop the growth as soon as you see a jump in bounces, a clear drop in opens or the first deferrals. You do not wait for the trend to confirm itself. Domain warmup runs in parallel the whole time, including when the IP is shared - then the domain is the only counter that belongs to you alone.
What to measure every day
Split bounces into hard and soft, broken down by recipient domain. The difference between hard and soft bounces decides whether you remove an address right away or give it a few more tries. An aggregate figure hides a local problem, and local problems are exactly the ones that show up most often.
Read the SMTP codes and the text of the server response. A deferral is a warning: the server is asking you to slow down and will give you a chance. A rejection is a decision - the message will not arrive, and retrying makes things worse. Telling those two apart flips your reaction a hundred and eighty degrees.
You get the complaint rate from feedback loops. A single threshold breach at one provider is a signal to pull volume back, not to debate. Treat opens and clicks as an engagement signal, but keep privacy protection in mail clients in mind: some opens are inflated by image prefetching. Clicks are more honest.
Unsubscribes are a healthy signal, not a failure. A recipient who unsubscribes will not report you as spam - and that report costs far more. On top of that comes monitoring of blocklists and of provider tools for checking domain reputation.
Tip: keep your own log. Date, volume, segment, result, every unusual server response. Without it you will not reconstruct the moment something broke, and the cause usually sits three days before the symptom.
When something goes wrong: deferrals, blocks, digging yourself out
First reaction: drop the volume back to the previous week’s level. But do not stop sending completely. Silence is a signal too, and a break in the rhythm undoes part of what you have built.
Read the rejection message instead of guessing. Providers say plainly what bothers them: too high a rate, complaints, an authentication problem, a blocklist entry. The response text sometimes even includes a link to a page describing the specific policy. It is the cheapest diagnostics you have.
Deferrals at one provider with clean results everywhere else mean a local problem. Do not rebuild the whole configuration then - slow down for that one domain and check what you sent to its recipients in recent days. File delisting requests only after fixing the cause. Ones filed earlier usually come back refused, and the next ones carry less weight.
Recovery looks the same as the start: you go back to the most active cohort and let it rebuild the signal. From our fleet we know that blocks happen even with fully correct SPF, DKIM and DMARC - all it takes is a volume spike or an old list let into a campaign by mistake. I have seen it happen several times. Be honest with yourself: some effects only show up after weeks, and no tool and no provider will guarantee the inbox.
Content and cadence during the warmup
Keep the first sends simple. Few images, few links, one domain in the links. The fewer elements, the fewer reasons for suspicion and the easier it is to point at the cause when something starts falling apart.
The sender has to be consistent. The same name in the From field and the same address throughout the cycle. A change halfway through the warmup means a new sender as far as the filter is concerned. Write subject lines without artificial urgency and without exclamation marks - that is part of the assessment too, alongside the technical side of the message.
Link shorteners and third-party redirect domains make the start worse. Your links should go through your domain, the same one you sign with DKIM. Recipient activity data is also better kept in-house, so it is worth checking the available CRM and e-commerce integrations instead of pushing traffic through intermediaries. And separate transactional messages from marketing ones: separate streams, separate subdomains, separate reputation. An order confirmation should not share the fate of a newsletter.
If you want control over the pace and full visibility into server responses, see how sending from the MailCraft fleet works. We run it ourselves, so you set the warmup schedule to fit your list rather than someone else’s infrastructure limits.
Summary: warmup is a process, not a one-off
Eight weeks gives you structure, but the outcome is decided by how you react to data, not by the calendar. Seeing deferrals in week five? Go back to week four. Everything clean - move on. The schedule is a frame, not a promise.
Once the warmup is over, keep sending regularly. A few weeks off undoes part of the effect, and when you come back you have to warm up again, though for a shorter time. List hygiene should be a permanent part of the work, not something you do before the holidays - removing inactive and hard-bouncing addresses does more for deliverability than changing the template.
Legal compliance and real recipient consent are the foundation, not a formality to tick off. A list built honestly generates the signals filters look for on its own.
A short checklist to start with:
- Authentication - SPF, DKIM, DMARC, Return-Path and PTR verified with a test send.
- Segmentation - cohorts by activity, inactive recipients outside the cycle.
- Schedule - fixed days and hours, gradual growth, a separate pace for large providers.
- Measurement - bounces, SMTP codes, complaints, unsubscribes, all broken down by domain.
- Reaction plan - a threshold agreed in advance at which you pull volume back.


