A founder running a lean, signal-based outbound motion does everything right. Three tiers of buying signals, a cadence that fires within 48 hours of a trigger event, copy that references the actual reason for the outreach instead of a template. Reply rates should climb. Instead they flatline, or worse, quietly drop to zero, and every obvious lever, tighter targeting, sharper copy, a new tool, makes no difference.
The reason is rarely in the CRM. It is in the domain. Somewhere between choosing an outbound tool and hitting send, most early-stage teams treat deliverability as a setup task, done once and forgotten. As of late 2025, that assumption is expensive. Google, Microsoft and Yahoo have all moved to strict, published thresholds for bulk senders, and the margin that used to let an otherwise-solid sender absorb a setup mistake is gone. Deliverability is no longer a setting to revisit if open rates look soft. It is a prerequisite decision that has to be made correctly before a single email goes out, because the system built on top of it, however well designed, cannot outrun a domain that has already lost the mailbox provider's trust.
What Actually Changed, and Why It Matters Now
Google's own sender guidelines are specific and unforgiving. Any account sending 5,000 or more emails a day to Gmail addresses must authenticate with SPF, DKIM and a valid DMARC record, support one-click unsubscribe, and keep its spam complaint rate below 0.3 percent, with Google's own guidance pointing senders toward a practical ceiling closer to 0.1 percent. Cross the 0.3 percent line and a sender loses access to Gmail's delivery mitigation support until it holds below that threshold for seven consecutive days.
Microsoft has followed a similar path, but with a harder edge. Its own published guidance requires SPF, DKIM and a DMARC policy for any sender exceeding 5,000 messages a day to Outlook.com, Hotmail.com or Live.com. Since May 2025, mail that fails those checks is not routed to a spam folder. It is rejected outright, with error code 550 5.7.15, meaning it never reaches the recipient in any form.
Industry reporting on Gmail's enforcement approach describes a further shift worth taking seriously: a move from reputation-based enforcement, where an established sender's history could offset an occasional lapse, to compliance-based enforcement, where meeting every requirement is what matters, not how long the domain has been sending. That specific characterization comes from trade coverage of the policy rather than a direct Google statement, but it matches what the published thresholds now imply. There is no visible allowance in the current rules for a sender who is usually careful.
None of this is happening in a vacuum. Cold email benchmark reporting from multiple providers this year points to platform-wide reply rates continuing to decline as inbox competition and filtering both intensify, alongside average bounce rates in the 7 to 8 percent range industry-wide. Benchmark reporting also notes that the senders holding reply rates in double digits are rarely just writing better copy. They are the ones whose infrastructure never gave the mailbox provider a reason to look twice.
The Thresholds, Without the Marketing Language
Strip away the vendor checklists and three numbers matter more than anything else in a domain audit.
Authentication is binary. SPF and DKIM must both be correctly configured, and DMARC must be published and aligned with at least one of them. This is not a "recommended" setup step at any meaningful send volume. It is the difference between mail that is evaluated on its content and mail that is rejected before evaluation happens.
Spam complaints are the number that actually governs trust. Google's stated ceiling is 0.3 percent, with a stricter practical target near 0.1 percent. A complaint rate that looks fine in isolation, one or two recipients marking a message as spam out of a few hundred sent, can still cross that line at volume, and once it does, recovery takes a minimum of seven clean days, not a settings change.
Bounce rate is the early-warning signal most founders ignore until it is too late. An acceptable bounce rate now sits under 3 percent; the 7 to 8 percent industry average is itself evidence that most senders are already operating with a compromised list, a cold domain, or both.
A founder who cannot state their current numbers on these three measures does not have a targeting problem to diagnose. They have a visibility problem, and no amount of message refinement will show up in the numbers until it is fixed.
Why the Build Order Has to Change
The instinct, understandably, is to design the outbound system first: define the signal tiers, write the cadence, draft the messaging, then plug it into whatever tool is fastest to set up. That order made sense when deliverability was forgiving. It does not make sense now.
A signal-based cadence is only as good as its ability to reach an inbox at all. Getting the timing and targeting right and then discovering the domain has crossed a spam-complaint threshold does not produce a mediocre result. It produces zero result, because rejected or filtered mail carries no signal back into the system that would explain why. The founder sees flat numbers and assumes the strategy failed, when the strategy was never actually tested.
This is a sequencing argument, not a technical one. Domain setup, authentication, and a genuine warm-up period belong before cadence design, not alongside it or after it. A domain that has been properly authenticated and warmed for several weeks before the first real send has room to absorb the normal variance of a live campaign. A domain sending at volume on day one, on the theory that the messaging strategy is what will be tested, is gambling infrastructure trust against a hypothesis that may never get a fair read.
Completing the System, Not Replacing It
None of this changes what actually works once a message reaches an inbox. A tiered signal stack, a cadence that fires inside 48 hours of a real trigger, and disciplined targeting over broad volume remain the right way to run outbound without a dedicated SDR, and RivoAxis's signal-based outbound framework still describes how to build that system correctly. What changes is what has to be true before that system is switched on.
The same logic applies to tool choice. The comparison in RivoAxis's Clay versus Apollo analysis was never just about features, it was about buying the right layer for the stage a company is actually at. Deliverability infrastructure is the layer beneath both of those decisions: the domain has to be sound before it matters which orchestration tool sits on top of it.
Where This Argument Has a Limit
None of this is new protocol. SPF, DKIM and DMARC have existed for years, and "warm up your domain" is advice that predates any 2025 policy change. A reasonable objection is that this is the same guidance repackaged with a new date attached to it.
The mechanics are not new. What has changed is the enforcement, and specifically the removal of the margin that used to let a sender with a decent track record absorb an occasional lapse. A founder who set up authentication correctly two years ago and has not touched it since is not automatically safe. Aggregators, list changes, a new sending tool added without updating SPF, or a slow drift in complaint rate can each quietly cross a threshold that used to be forgiving and now is not. This argument does not apply to teams already tracking their authentication status and complaint rate as an ongoing discipline rather than a one-time task. It applies to the much larger group treating deliverability as something they configured once.
What to Check Before the Next Send
Before adjusting a single line of cadence or copy, confirm three things: that SPF, DKIM and DMARC are correctly aligned on the sending domain, that the current spam complaint rate is known and sits meaningfully under 0.3 percent, and that bounce rate is under 3 percent on the active list. If any of those cannot be answered with a real number, that is the actual bottleneck, not the messaging strategy sitting on top of it.
RivoAxis works with early-stage teams to build outbound systems where the infrastructure, the targeting and the cadence are designed in the right order from the start, rather than debugged in the wrong one after the numbers have already gone flat. If a signal-based system is underperforming and the cause has not been diagnosed past "reply rates dropped," that diagnostic is the right place to start.
Talk to RivoAxis about your outbound system
