mailwel
Controllables · updated 2026-04-11

Infrastructure & Routing Strategies

Infrastructure Is Reputation

Your sending infrastructure is not just plumbing — it is identity. Mailbox providers build reputation profiles tied to your IP addresses and domains. The architectural decisions you make about IPs, domains, and routing directly shape how providers perceive and score your mail.


IP Strategy: Shared vs. Dedicated

Shared IPs

On a shared IP pool, your mail is sent from the same IP addresses as other customers of your ESP. This means:

Advantages:

  • No warmup required — the pool already has established reputation
  • Volume fluctuations are smoothed across many senders
  • Lower cost — no need for dedicated infrastructure
  • Good for low-volume senders (under 50,000 emails/month)

Disadvantages:

  • You inherit the pool’s reputation — if another sender spams, your mail suffers
  • You have no individual control over IP reputation
  • Monitoring is limited — you can’t isolate your IP-specific performance
  • Quality depends entirely on the ESP’s enforcement of sending policies

When shared IPs work well:

  • Low-volume senders who can’t sustain dedicated IP reputation
  • Senders using high-quality ESPs with strict enforcement (Postmark, for example, is known for aggressive sender screening)
  • Transactional-only senders with inherently high engagement

When shared IPs fail:

  • When your ESP allows low-quality senders on the same pool
  • When you can’t distinguish your reputation from the pool’s
  • When you need granular control for multi-provider optimization

Dedicated IPs

A dedicated IP carries only your sending reputation. You control it entirely.

Advantages:

  • Full control over reputation — your behavior, your consequences
  • Ability to monitor and manage IP reputation directly
  • Isolation from other senders’ problems
  • Required for some certification programs (e.g., Validity/Return Path certification)

Disadvantages:

  • Requires warmup from scratch — a new dedicated IP has zero reputation
  • Needs consistent volume to maintain reputation (generally 50,000+ emails/month)
  • Low-volume periods can cause reputation to “go cold”
  • You bear full responsibility for any reputation damage

Warmup protocol for dedicated IPs:

Week Daily Volume Target
1 50–200 Most engaged recipients only
2 200–1,000 Expand to recent engagers (30 days)
3 1,000–5,000 Expand to 60-day engagers
4 5,000–20,000 Expand to 90-day engagers
5–8 Ramp to target Gradually include full list

Key warmup principles:

  • Start with your most engaged recipients — their positive interactions build IP trust fastest
  • Increase volume by no more than 2x per day
  • Monitor bounces, complaints, and placement at every step
  • If metrics degrade, reduce volume and investigate before continuing
  • Different providers warm at different rates — Gmail is generally more forgiving than Microsoft

IP Pools

Some ESPs offer IP pool management, where you maintain multiple dedicated IPs and distribute traffic across them:

  • Round-robin: Traffic is distributed evenly across all IPs in the pool
  • Weighted: Higher-reputation IPs receive more traffic
  • Segmented: Different IP pools for different mail types (transactional vs. marketing)

IP pools provide redundancy and allow you to scale without overloading individual IPs. They also let you isolate different sending streams to protect reputation.


Domain Strategy

The Sending Domain Hierarchy

A mature sending operation typically uses multiple domains and subdomains:

example.com                    — Corporate domain (website, employee email)
├── mail.example.com           — Transactional email (receipts, password resets)
├── news.example.com           — Marketing newsletters
├── outreach.example.com       — Sales/prospecting email  
└── notifications.example.com  — Product notifications

Why Subdomain Separation Matters

Each subdomain builds its own reputation at most providers. This means:

  • A spam complaint spike on news.example.com doesn’t directly damage mail.example.com
  • You can apply different DMARC policies per subdomain
  • You can use different IPs per subdomain
  • Monitoring and troubleshooting is cleaner when each stream is isolated

Critical rule: Never send marketing or outreach email from your primary corporate domain. If marketing mail damages example.com reputation, it can affect employee email deliverability as well.

Domain Age and History

Mailbox providers consider domain age as a trust signal:

  • Brand new domains (< 30 days): Treated with maximum suspicion. Providers may heavily throttle or spam-filter all mail.
  • Young domains (1–6 months): Building initial reputation. Volume must be low and engagement must be high.
  • Established domains (6+ months): Have enough history for providers to form a reliable reputation model.
  • Aged domains (1+ year with clean history): Carry significant trust weight.

Don’t burn domains. Some senders treat domains as disposable — when one gets a bad reputation, they register a new one. Providers have adapted to this by being extra suspicious of new domains. Building a single strong domain reputation is far more effective than cycling through disposable ones.

Domain Authentication Architecture

Each subdomain needs its own authentication setup:

mail.example.com
├── SPF: v=spf1 include:amazonses.com -all
├── DKIM: selector._domainkey.mail.example.com → public key
└── DMARC: _dmarc.mail.example.com → v=DMARC1; p=reject; ...

news.example.com  
├── SPF: v=spf1 include:sendgrid.net -all
├── DKIM: selector._domainkey.news.example.com → public key
└── DMARC: _dmarc.news.example.com → v=DMARC1; p=reject; ...

If a subdomain doesn’t have its own DMARC record, it inherits the parent domain’s policy. This can be intentional (centralized policy) or a gap (subdomain mail fails unexpected checks).


Routing Architecture

Single-ESP vs. Multi-ESP

Single-ESP approach:

  • Simpler management
  • Unified analytics
  • Single point of failure
  • Limited ability to optimize per-provider

Multi-ESP approach:

  • Route different mail types through different ESPs optimized for each
  • Example: Postmark for transactional (optimized for speed and inbox placement), SendGrid for marketing (optimized for volume and templates)
  • Redundancy: if one ESP has an outage, critical mail can failover
  • Complexity: managing authentication, reporting, and reputation across multiple systems

Smart Routing

Advanced sending operations implement smart routing based on:

  • Provider-based routing: Send Gmail-destined mail through one ESP and Outlook-destined mail through another, optimized for each provider’s preferences
  • Engagement-based routing: Route mail to highly engaged recipients through your best-reputation infrastructure
  • Content-based routing: Transactional mail through low-latency, high-reputation channels; marketing through volume-optimized channels
  • Failover routing: If primary ESP bounces or throttles, automatically retry through backup infrastructure

Connection Management

How you connect to receiving servers matters:

Connection concurrency: Each provider has implicit or explicit limits on simultaneous connections from a single IP. Exceeding these limits triggers throttling (421 rejections).

Retry behavior: When a provider returns a temporary failure (4xx), smart retry logic backs off exponentially rather than hammering the server. Aggressive retry patterns are a negative signal.

TLS: Always use opportunistic TLS. Most major providers support TLS and some (Google) publicly report the percentage of inbound mail that uses encryption.

IPv6: Gmail and some other providers support IPv6 for inbound mail. IPv6 reputation is tracked separately from IPv4. If you send over IPv6, you need to warm and manage that reputation independently.


Monitoring Infrastructure Health

What to Monitor

Metric Tool Alert Threshold
IP reputation Google Postmaster, SNDS Medium or below
Domain reputation Google Postmaster Low or Bad
Blocklist status MXToolbox, Spamhaus check Any listing
Bounce rate ESP dashboard Above 2% per campaign
Complaint rate FBL reports, Postmaster Above 0.1%
Delivery latency ESP logs Sustained delays > 30s
TLS success rate ESP logs Below 95%
Authentication pass rate DMARC reports Below 98%

Blocklist Monitoring

Check your sending IPs and domains against major blocklists regularly:

  • Spamhaus SBL/XBL/DBL — Most impactful; used by the majority of providers
  • Barracuda BRBL — Common in corporate environments
  • SpamCop — Complaint-driven; listings auto-expire
  • SORBS — Aggregated list; check for false positives
  • URIBL/SURBL — URL-based; check your link domains

Automated monitoring tools can check these lists and alert you immediately when a listing appears. Early detection is critical because the impact of a blocklisting grows with every hour it remains in place.


Practical Infrastructure Checklist

For a well-configured sending infrastructure:

  • Dedicated IP(s) for volume above 50K/month, shared for below
  • Separate subdomains for transactional, marketing, and outreach
  • SPF records for each sending subdomain (under 10 lookups)
  • DKIM signing with your own domain at each ESP
  • DMARC at enforcement level (quarantine or reject) with reporting
  • Reverse DNS configured for all sending IPs
  • TLS enabled for all connections
  • Blocklist monitoring for all sending IPs and domains
  • Google Postmaster Tools configured
  • Microsoft SNDS enrolled
  • Feedback loops registered where available
  • IP warmup plan for any new dedicated IPs
  • Connection rate limits configured per destination provider
  • Retry logic with exponential backoff

Infrastructure decisions are among the hardest to change once established. Getting the architecture right from the start saves significant time and prevents reputation damage that can take weeks to recover from.