Cold Email Domain Setup: Secondary Domains, Naming and Redirects
Domains are the foundation your whole sending reputation sits on — and the part people cheap out on most. After registering and configuring thousands of sending domains across client fleets, this is the setup that survives contact with spam filters.
Never send from your main domain
Your primary domain carries your company's entire email existence: client threads, invoices, password resets. Cold outreach generates complaints even when done well — that risk belongs on secondary domains you can afford to lose. If a sending domain burns, you rotate it out; if your main domain burns, you have a company-wide incident.
Naming that looks human
Recipients (and filters) see the from-domain. It should look like a natural brand property, not infrastructure:
At fleet scale you're generating hundreds of names — I script the generation, then filter by hand, because one tone-deaf name pattern repeated across 50 domains is a fingerprint.
The per-domain build checklist
Register & consolidate
Buy on a registrar you can automate (Namecheap, Porkbun, Cloudflare). Keep the fleet in as few accounts as possible.
DNS zone + records
Create the zone, then MX → SPF → mailboxes → DKIM (enabled, not just published) → DMARC at p=none.
Redirects
301 the apex and www of every sending domain to your primary site.
Tracking domain
CNAME a subdomain (track.getacme.com) to your sending tool — never the shared default.
Full-fleet auditing
Fleets drift: registrars change nameservers, a tool overwrites a record, someone “cleans up” DNS. I audit every domain's SPF/DKIM/DMARC state on a schedule — it's how I've caught things like DKIM silently broken across hundreds of Microsoft domains before it flattened a quarter's pipeline. Once domains are built, size the fleet with the capacity math and ramp with the warmup schedule.
Which TLD, and what a domain should cost
Buy .com if it is available and .co, .io or .net if it is not, in that order. Filters do not score TLDs the way people assume, but people do: a prospect who hovers and sees getacme.xyz reads it as disposable, and a domain that looks disposable to a human tends to be one that spammers also bought in bulk, which is what trains the filter. Avoid the cheap-first-year TLDs entirely for the same reason — .xyz, .top, .click, .site and the rest are dominated by abuse and a new domain on them starts with that reputation.
Expect to pay $9–14 a year for .com at a real registrar and treat anything much cheaper as a first-year promotion with a renewal you have not read. Buy two-year terms on domains you intend to keep; registration length is a weak but real age signal, and a fleet that all expires on the same day is a fleet you will forget to renew. The availability checker checks a list of candidates in one pass, and the expiry checker catches the renewal you missed.
Redirect rules that keep the brand safe
Every secondary domain should redirect to the main site, and never the other way round. A 301 from the root and from www to https://acme.com is enough; do not host a copy of the site on the secondary, do not put a landing page there, do not run a form. A secondary domain that serves content is a domain that can be reported for phishing when its content looks like a lookalike of yours — because it is one.
The redirect also does something quieter. A prospect who checks where getacme.com goes lands on your real site, which is the difference between "cold email from a fake domain" and "cold email from a company I can look up". The redirect checker confirms each secondary resolves to the main site in one hop with a valid certificate, which is also what the link scanners on the receiving side will check.
Registrar and DNS: keep them separable
Register at a registrar you would trust with the main domain and point the nameservers at Cloudflare, so every zone in the fleet has the same API, the same record editor and the same bulk path. Do not use registrar-hosted DNS across a fleet; the moment you need to change a DMARC policy on forty domains, forty different control panels is the reason it does not happen. With one DNS provider it is one script, or one CSV through the email DNS setup tool, which generates and applies the full record set per domain.
Keep the registrar and the DNS provider as two accounts, not one. If the registrar account is compromised the domains can be transferred out; if the DNS account is compromised the records can be changed. Two credentials, two-factor on both, and a nameserver audit once a quarter — the NS checker shows a whole list of domains and flags any that have drifted off the provider you expect.
For a 5–50 domain batch, Namecheap is the simplest place to start: bulk search, free WHOIS privacy on every name, and an API for the automation in the checklist above. Point the nameservers at Cloudflare afterwards and manage DNS there.
Search domains on Namecheap →Affiliate link — it costs you nothing and helps keep this site free.Check the name before you buy it
Run each candidate through the lookalike domain checker. A secondary domain that is one character from another company's name is a lookalike of theirs, and a takedown letter arrives faster than replies do.
Tools for this
Domain availability checkerFree or taken, straight from the registry.Domain expiry checkerWhich of your domains expire next, from the registry.Redirect checkerTrace a redirect chain to its final URL.Email DNS setupGenerate and apply email DNS records.Frequently asked questions
What domains should I buy for cold email?
Buy close variants of your real brand on .com first — get-brand, try-brand, brand-hq, brandapp — so recipients who check the domain land on something coherent. Avoid hyphen-stuffed keyword domains and cheap novelty TLDs, which pattern-match spam and erode trust.
Should cold email domains redirect to my main website?
Yes, always — a 301 redirect from every sending domain (and its www) to your primary site. Prospects and spam filters both check the domain; a dead page reads as disposable spam infrastructure, a clean redirect reads as a legitimate brand property.
How long after buying a domain can I send cold email from it?
Let DNS settle and authentication verify, then warm for two to four weeks before meaningful volume. Practically, a new domain is doing real campaign work about a month after purchase — which is why fleets always keep a warming pipeline running.
Should I buy the domains under my own name or the client's?
The client's, always, when you are building for someone else. Domains registered to an agency are the single most common thing clients lose when the relationship ends, and a sending domain with a year of reputation is worth more than the agency fee that month. Register in the client's account, or transfer the moment the engagement starts, and manage through delegated access.
Does the age of a domain still matter?
Less than it used to, but it is not zero. A domain registered last week and sending cold email this week fits the pattern receivers are trained on, and every other signal has to work harder to overcome it. Two to four weeks between registration and first campaign, with warmup running, is the practical minimum; buying domains in advance of when you need them is the cheap way to get there.
Can I reuse a domain that was burned on a previous fleet?
Sometimes. A domain that went to junk from over-sending recovers with months of rest and a careful re-warm. A domain that was listed on Spamhaus DBL for spam-trap hits or was reported for phishing usually does not, because the record follows the domain. Check the domain's history and blacklist status before you spend the warmup time on it — it is often cheaper to buy a fresh one.