Introduction

Cold email outreach is a numbers game, but the numbers that matter most are not just open rates and replies. Deliverability is the foundation. If your emails don't land in the inbox, nothing else matters. A recent longitudinal study of approximately 1.52 million malicious domains observed on VirusTotal between January and May 2026 provides a unique lens through which to examine email deliverability risks. While the study focuses on cybersecurity, its findings about domain characteristics, infrastructure, and abuse patterns offer practical lessons for anyone running cold email campaigns.

The Study at a Glance

The paper, "A Longitudinal Study of Recently Observed Malicious Domains: Characteristics, Infrastructure, and Abuse," analyzed a massive dataset of domains flagged as malicious. Although the primary goal was to understand how attackers operate, the data reveals patterns that are directly relevant to email senders. For instance, many malicious domains are registered in bulk, use suspicious registrars, and are short-lived. These same traits can trigger spam filters and damage sender reputation.

Lesson 1: Domain Reputation Is Everything

Email providers like Gmail and Outlook use complex algorithms to determine whether an email should land in the inbox or spam folder. A key factor is the reputation of the sending domain. If your domain shares characteristics with known malicious domains, your deliverability will suffer. The study found that malicious domains often have low age, use privacy protection, and are hosted on cheap or bulletproof infrastructure. As a cold email sender, you should avoid these red flags:

  • New domains: Sending cold emails from a domain that is only a few days old is risky. Build domain age gradually by sending a small volume of warm-up emails first.
  • Suspicious registrars: Use reputable domain registrars and avoid those commonly associated with spam.
  • Mismatched WHOIS: Ensure your domain's WHOIS information is consistent and legitimate.

Lesson 2: Authentication Is Non-Negotiable

The study highlights that malicious domains often lack proper email authentication. In contrast, legitimate senders must implement SPF, DKIM, and DMARC to prove they are not spoofing. According to general industry knowledge, these protocols help mailbox providers verify that an email is genuinely from the domain it claims to be from. Without them, your emails are more likely to be flagged as spam or rejected.

  • SPF (Sender Policy Framework) specifies which servers are allowed to send email for your domain.
  • DKIM (DomainKeys Identified Mail) adds a digital signature to your emails.
  • DMARC (Domain-based Message Authentication, Reporting, and Conformance) tells receivers how to handle emails that fail SPF or DKIM.

Implementing all three is a baseline requirement for cold email in 2026.

Lesson 3: List Hygiene Prevents Association with Malicious Activity

One of the study's key findings is that malicious domains often target email addresses that are either harvested or purchased. As a cold email sender, you must ensure your list is built ethically and cleaned regularly. Sending to invalid or outdated addresses increases bounce rates, which harms your sender reputation. The average cross-industry email bounce rate in 2026 is 1.2%, so aim to keep yours below that threshold.

  • Use email verification services to remove invalid addresses before sending.
  • Remove hard bounces immediately.
  • Monitor complaint rates and remove unengaged recipients.

Lesson 4: Volume and Sending Patterns Matter

The study observed that malicious domains often send bursts of emails from a single IP address. This behavior is a classic spam signal. For cold email, you should:

  • Warm up new IPs and domains: Gradually increase sending volume over days or weeks.
  • Limit daily sends per domain: Many experts recommend no more than 50-100 emails per day per domain initially.
  • Use multiple domains and IPs: Distribute your sending across several domains to reduce the impact of any single domain's reputation.

Lesson 5: Monitor Your Reputation Continuously

Just as the study tracked malicious domains over time, you should monitor your own sending reputation. Tools like Google Postmaster Tools and Microsoft SNDS provide data on spam complaints, delivery errors, and reputation. Inbox placement rates vary by industry, with 2026 benchmarks showing rates from 79% (real estate) to 93% (non-profit). If your inbox placement drops, investigate immediately.

Practical Steps for Cold Email Senders

Based on the study's insights and general best practices, here is a checklist to protect your deliverability:

  1. Use a dedicated sending domain that is at least a few months old.
  2. Authenticate with SPF, DKIM, and DMARC (set DMARC to p=quarantine or p=reject after monitoring).
  3. Verify your email list before every campaign.
  4. Start with low volume and increase gradually.
  5. Monitor bounce rates, spam complaints, and inbox placement regularly.
  6. Avoid using free email services (e.g., Gmail, Yahoo) for cold outreach.
  7. Keep your domain WHOIS information accurate and use a reputable registrar.

Conclusion

The study of 1.52 million malicious domains is a stark reminder that email infrastructure is constantly under scrutiny. While your cold email campaigns are legitimate, you must avoid behaviors that resemble malicious activity. By focusing on domain reputation, authentication, list hygiene, and sending patterns, you can maximize inbox placement and keep your outreach effective. In 2026, deliverability is not just a technical detail; it is the backbone of any successful cold email strategy.