Pick a domain, choose how many mailboxes, and OneMail registers it, publishes MX, SPF, DKIM and DMARC correctly the first time, creates the mailboxes, and hands them to warmup already connected.
Setting up a cold-sending domain properly means registering it, pointing MX at a mail host, publishing an SPF record that does not exceed the lookup limit, generating a DKIM key pair and publishing the public half at the right selector, adding a DMARC policy, and creating a bounce subdomain with its own MX and SPF. OneMail does all of it and then verifies that what it published actually resolves.
You do not have to buy through us. If the domain is somewhere Warmerly can reach — or you would rather publish the records yourself — OneMail generates the exact record set for that domain and checks each one until it resolves, so a typo in a DKIM key surfaces immediately rather than as an unexplained placement problem three weeks later.
More than one SPF record at a name is a permanent error under RFC 7208, and more than one DMARC record means the policy is discarded entirely and silently. Publishing into a zone that already has records is exactly where this goes wrong. OneMail's publisher treats name plus record type as the identity for these two, merging rather than duplicating, because a second record does not add protection — it removes it.
The hardest part of cold email is not writing the sequence. It is standing up sending infrastructure that is authenticated correctly, separated from your main domain, and spread across enough domains that one reputation problem does not take everything down. OneMail is that job, done for you, in one flow.
Reputation is scored at the domain level. If you send cold outreach from the domain that also carries your invoices, your support replies and your password resets, then every complaint, every bounce and every spam-folder placement from that outreach is charged against the domain your business depends on. Recovering a damaged primary domain is measured in months.
The standard answer is a separate sending domain — a lookalike of your brand, registered specifically for outreach, with its own reputation to build and its own reputation to risk. If it gets damaged you retire it. That is a cost of doing business rather than a crisis.
Concentrating every mailbox on a single sending domain gives you one reputation and one failure that takes all of your capacity at once. Several domains with a handful of mailboxes each is the shape that survives a bad month.
DMARC deliberately starts at p=none. Publishing p=reject on a brand-new domain before you have observed what actually sends as it is the fastest way to have legitimate mail silently disappear. Move to quarantine once the picture is clean.
The most expensive class of DNS bug is the one where the record was written and nobody checked it resolved. A DKIM key truncated on paste, a TXT record wrapped by a control panel, a zone that was not the zone actually serving the domain — all of these look like success in the panel and produce authentication failure at the receiver.
OneMail resolves each record after publishing and keeps checking until every one answers correctly. A domain does not become Active in the interface until it does. The status you see is the resolver's opinion, not the API call's return value.
Each stage is visible while it happens, including the failures. A registration that fails, a DNS record that will not verify, a mailbox that could not be created — all of them show as a state with a reason rather than as a spinner that never resolves.
Correct authentication removes an entire category of problem, but it does not buy reputation. A domain registered today has no history, and providers treat young domains with justified suspicion because throwaway domains are the classic spam pattern. Perfect DNS on a three-day-old domain sending two hundred cold emails will still be filtered.
This is why OneMail hands mailboxes straight to warmup rather than to your campaigns. The domain needs weeks of ordinary, engaged correspondence before it can carry meaningful cold volume, and the ramp is derived from its real age rather than from your launch date. It is the least convenient part of the product and the part most worth respecting.
No. OneMail can register one for you, or generate and verify the full record set for a domain you already own. The verification loop is the same either way.
Provisioning and DNS verification typically complete within the hour, subject to registration and propagation. Being ready for real cold volume is a separate question — plan on two to four weeks of warmup on a newly registered domain.
p=none initially, so you can observe what authenticates before anything gets rejected. Tightening to quarantine once the picture is clean is the right next step.
So bounce handling has its own MX and SPF and does not have to share the apex. It is a small detail that most setup guides skip and that causes odd, hard-to-diagnose failures later.
The domain is yours. The mailboxes are hosted by us, so moving means standing them up on another host and re-pointing MX — the same as any mail migration.
Registered, authenticated, verified and warming — without you opening a DNS panel or generating a DKIM key by hand.