Infrastructure & Routing Strategies
Learn how your sending IPs, domains, and routing choices impact reputation.
Every email leaves from an IP address (the numeric address of the sending server) and uses a domain, like shop.example. Gmail, Outlook and Yahoo keep a reputation for each one, based on how its mail behaved before. This article explains how to choose your IPs, split your mail across subdomains, and route and monitor it. These choices are hard to change later, so get them right early.
Shared or dedicated IPs
Your email service provider (ESP, the company that sends your email, such as Postmark or SendGrid) usually offers two options.
Shared IPs
On a shared IP, your mail goes out from the same addresses as other customers of your ESP.
Good:
- No warm-up needed. The IPs already have a history.
- Busy and quiet weeks average out across many senders.
- Cheaper.
Bad:
- If another customer sends spam, your mail can suffer too.
- You can’t see or manage the IP’s reputation yourself.
- Quality depends on how strictly your ESP polices its customers.
Shared IPs suit modest volumes (many ESPs draw the line around 50,000 emails a month) and transactional mail (receipts, password resets) that people expect. Pick an ESP known for screening its customers.
Dedicated IPs
A dedicated IP sends only your mail. Its reputation is yours alone.
Good:
- Your results depend only on your own sending.
- You can watch the IP’s reputation directly.
- Other senders’ problems don’t reach you.
Bad:
- A new IP has no history. You must warm it up (build trust slowly, see below).
- It needs steady volume. If you send rarely, providers forget it and it goes “cold”.
- Any damage is entirely yours to fix.
Warming up a new IP
Providers distrust a new IP that suddenly sends a lot. Start small and grow week by week, sending first to the people most likely to open:
| Week | Emails per day | Who gets them |
|---|---|---|
| 1 | 50–200 | Your most engaged readers |
| 2 | 200–1,000 | People who opened in the last 30 days |
| 3 | 1,000–5,000 | People who opened in the last 60 days |
| 4 | 5,000–20,000 | People who opened in the last 90 days |
| 5–8 | Up to your normal volume | The rest of your list, gradually |
- At most double your volume from one day to the next.
- Check bounces, spam complaints and inbox placement after every step.
- If the numbers get worse, send less and find the cause before you continue.
- Each provider learns at its own pace. You may be in Gmail’s inbox before Outlook’s.
IP pools
Larger senders use a pool of several dedicated IPs. Mail can be spread evenly, weighted toward the IPs with the best reputation, or split by type: one pool for transactional mail, one for marketing. Pools let you grow without overloading one IP, and keep one kind of mail from hurting another.
Domains and subdomains
Split your mail by type
A subdomain is a name under your main domain, like news.shop.example under shop.example. Giving each kind of mail its own subdomain keeps their reputations apart:
shop.example — website and staff email
├── orders.shop.example — receipts, password resets
├── news.shop.example — newsletters and promotions
├── outreach.shop.example — sales prospecting
└── notify.shop.example — product notifications
With this split:
- A spike of spam complaints on
news.shop.exampledoes less harm toorders.shop.example. - You can give each subdomain its own IPs and its own DMARC policy.
- Problems are easier to spot, because each stream has its own numbers.
Providers do still connect subdomains to the main domain. Separation limits the damage. It doesn’t give a badly behaved subdomain a clean slate.
Don’t send marketing from the domain your staff use. If newsletters hurt shop.example, everyday mail from your team can start landing in spam too.
Domain age
A domain registered last week that sends thousands of emails looks like a spammer. Trust builds over months of steady, clean sending. Start a new domain slowly, with your most engaged readers, just like a new IP.
Don’t treat domains as disposable. Some senders register a new domain whenever the old one gets a bad name. Providers know this trick, which is one reason they distrust new domains. One domain with a long, clean history is worth far more.
Authentication for every subdomain
Each subdomain you send from needs its own SPF, DKIM and DMARC records (see Authentication & Identity Control):
orders.shop.example
├── SPF: v=spf1 include:amazonses.com -all
├── DKIM: s1._domainkey.orders.shop.example → public key
└── DMARC: _dmarc.orders.shop.example → v=DMARC1; p=reject; ...
news.shop.example
├── SPF: v=spf1 include:sendgrid.net -all
├── DKIM: s1._domainkey.news.shop.example → public key
└── DMARC: _dmarc.news.shop.example → v=DMARC1; p=reject; ...
Here, orders sends through Amazon SES and news through SendGrid. Each SPF record lists only that subdomain’s sender, and each DKIM key lives under its own subdomain.
If a subdomain has no DMARC record of its own, receivers use the main domain’s record. They apply its sp= policy if it has one, or its p= policy if not. That can be what you want, or a gap you didn’t notice. Check each name with the DNS lookup tool.
Routing
Routing means deciding which service and which IPs each email goes out through.
One ESP or several
One ESP is simpler: one dashboard, one set of records. But if it has an outage, all your mail stops.
Several ESPs let you use each for what it does best, such as one for fast transactional mail and another for large newsletters. You also get a backup. The cost is managing authentication, reports and reputation in several places.
Ways to route mail
- By type: receipts and password resets through your fastest, best-reputation path; newsletters through a high-volume one.
- By engagement: mail for your most active readers through your best infrastructure.
- By provider: mail for Gmail through one route and mail for Outlook through another.
- Failover: if one ESP is down, send critical mail through a backup.
Use failover for outages, not to dodge a block. If a provider is slowing or rejecting your mail, sending the same mail through other IPs looks like evasion. Spammers spread mail across many IPs to stay under the radar, a practice called snowshoeing. Fix the cause instead.
How you connect
- Don’t open too many connections at once. Each provider limits how many simultaneous connections it accepts from one IP. Go over it and you get temporary rejections, usually SMTP code
421. - Back off when told to wait. A
4xxreply is a temporary failure. Retry after a delay, and make each delay longer than the last. Hammering the server makes things worse. - Always use TLS (encryption for the connection between servers). Gmail’s sender guidelines ask for it, and most ESPs turn it on for you.
- Treat IPv6 separately. Providers track IPv6 and IPv4 reputation apart. If you send over IPv6, warm it up and watch it on its own.
You can see how a receiving server answers your connection with the SMTP probe.
Monitoring
What to watch
| What | Where to see it | Worry when |
|---|---|---|
| Spam complaints | Google Postmaster Tools, feedback loops | Above 0.1% (Gmail and Yahoo require under 0.3%) |
| Bounces | Your ESP’s dashboard | Above 2% in a campaign |
| Blocklist listings | Blocklist checkers | Any new listing |
| Authentication | DMARC reports | Real mail failing SPF or DKIM |
| Microsoft data | Microsoft SNDS | Complaints or spam trap hits on your IPs |
| TLS | ESP logs | Mail sent without encryption |
Microsoft SNDS (Smart Network Data Services) shows data for each of your IPs. A feedback loop is a service where a provider tells you each time one of its users marks your mail as spam.
Blocklists
A blocklist is a public list of IPs or domains that sent spam. Many receivers refuse mail from anything on one. The main ones:
- Spamhaus: the most widely used. It lists IPs and, in its DBL, domains.
- Barracuda (BRBL): common at companies that use Barracuda filters.
- SpamCop: built from user reports. Listings expire on their own once the reports stop.
- URIBL and SURBL: list domains found in links inside spam. Check the domains you link to.
Set up automatic checks that alert you to a new listing. The longer a listing stays, the more mail you lose.
Checklist
- Shared IPs for modest volume; dedicated IPs once you send enough to keep them warm.
- A warm-up plan for every new IP and new domain.
- Separate subdomains for transactional mail, marketing and outreach.
- SPF (under 10 lookups), DKIM with your own domain, and DMARC for each sending subdomain.
- DMARC moving to
quarantineorreject, with reports. - Reverse DNS (a PTR record that maps the IP back to a hostname) on every sending IP.
- TLS on all connections.
- Google Postmaster Tools, Microsoft SNDS and feedback loops set up.
- Blocklist alerts for your IPs and domains.
- Connection limits per provider, and retries that wait longer each time.
Then send a message to the test inbox to confirm your authentication and setup.