RUEN
deliverability — 01 Aug 2026

A Separate Domain for Cold Email: Protecting Your Primary Domain

Why cold outreach should never run from your main corporate domain, how to pick and set up a secondary one, and where this setup usually breaks.

Cold outreach should run from a separate domain, not from your main corporate one. The reason is simple: mailbox providers — Gmail, Outlook, and in Russia Yandex and Mail.ru — score reputation at the level of the whole domain, not an individual mailbox. If recipients of your cold emails hit "report spam," the filter catches every message from that domain: the campaign, the invoice from accounting, and the email a long-standing client is actually waiting for.

The scheme that removes this risk looks like this: the primary domain stays untouched — only live business correspondence goes from it. Outreach runs from a neighboring domain: similar in name, properly dressed, and technically configured. Below is how to pick such a domain, how to make it look legitimate rather than fake, and where this setup usually falls apart.

What a company risks by sending cold email from its main domain

Domain reputation is a hidden score that mailbox platforms keep on every sender. It is shaped by spam complaints, bounce rates, sudden volume spikes, and missing authentication records. If you sell into Russia or the CIS, two receiving sides matter most: Yandex and Mail.ru — the majority of your counterparties' work inboxes live there, not on Gmail.

Cold email by definition collects more negative reactions than ordinary correspondence: some recipients will mark it as spam even when the message is relevant and well written. When that happens on your primary domain, the consequences arrive immediately and everywhere:

  • emails to existing clients and partners start landing in spam — you usually find out when a counterparty "never received" the invoice, the contract, or the proposal;
  • the domain ends up on internal blocklists, and mail stops being delivered at all;
  • in our experience, rebuilding reputation takes from several weeks to months — and during that whole period your main communication channel with the market works intermittently.

You cannot isolate risk inside one domain: the sales team's mailbox and the CEO's mailbox share the same reputation. The only working isolation is a separate domain.

How to choose the secondary domain

The goal is a domain that a recipient will easily connect to your company, and that mailbox systems won't read as disposable. The main reference points:

Parameter Good option Bad option
Name Mirrors the main brand: kapgrupp.com next to kapgrupp.ru A string of letters, digits and hyphens: kp-grupp-2026.ru
Zone .ru works fine for a Russian audience; .com is a solid option too Cheap exotic zones that spammers use in bulk
History A new domain, or one with a clean past A previously used domain that already sent spam
Other brands Your own name, even if slightly different A name resembling someone else's company — that's not a "neighbor domain," that's impersonation

Two practical notes. First, before buying, check the domain's history: what sites lived on it before and whether it appears on any blocklists. Second, if you plan to email Russian companies, avoid Cyrillic-only zones like .рф for mail — inside email protocols such a domain is encoded as a technical punycode string, and some systems handle it worse. For outreach into Russia, .ru remains the default working choice.

How to dress the domain so it doesn't look fake

The first thing a skeptical recipient does is type the sender's domain into a browser. If they get an error or an empty registrar placeholder page, the email earns no trust — and earns a complaint instead. The minimum kit:

  • A storefront. A redirect from the secondary domain to your main site, or a standalone page with the company name, description and contact details. Within ten seconds the recipient should understand who is writing to them.
  • Mail on a familiar platform. For Russian outreach, host the mailboxes on Yandex 360 for Business or Mail.ru for Business — to a recipient on those same platforms, the message looks "native" rather than arriving from an unknown server. For international recipients, Google Workspace or Microsoft 365 play the same role.
  • A real sender. The email comes from a specific person: first name, last name, title, phone number in the signature. Addresses like mailing@ or no-reply@ do not work for business outreach.
  • Several mailboxes. Spread volume across two or three addresses per domain instead of pushing everything from one — a spike from a single mailbox reads to filters as a blast.

The technical minimum: SPF, DKIM and DMARC

Three DNS records without which a domain effectively doesn't exist for outreach. SPF lists the servers allowed to send mail on behalf of the domain, DKIM signs each message with a key, and DMARC tells the receiving side what to do with a message that fails the checks. Since early 2024, Google and Yahoo require bulk senders to have SPF, DKIM and DMARC configured, one-click unsubscribe, and a spam-complaint rate kept low — this has de facto become the common standard, and Russian platforms check the same things. We published a detailed walkthrough of configuring these records for Yandex 360 and Mail.ru in our field notes.

Separately — warming up. A brand-new domain that sends hundreds of emails on day one looks to filters exactly like what it looks like: a spammer. For the first few weeks the domain works at low volumes, with live correspondence, and only then ramps up to planned load.

The legal frame: a domain doesn't cancel the rules

A frequent question: "If we write from a secondary domain, is that legal?" The legal status of an email is determined by its content, not by the sender's domain — and this holds in Russia just as it does under GDPR or CAN-SPAM elsewhere.

In Russia, advertising sent over communication networks — including email — requires the recipient's prior consent. The dividing line in practice: a mass, impersonal promotional blast without consent is a violation and can bring an administrative fine for the company, while a targeted business proposal addressed to a specific company about its own line of work is not treated as advertising. Complaints to the regulator arise over mass faceless mailings, not over genuine business correspondence.

A separate layer is personal data: a specific person's name, title and work email count as personal data under Russian law, much as they do under GDPR. Data a person has deliberately made public is regulated separately, but the safe working practice is familiar: prefer role-based corporate addresses like info@ and sales@ or data from open registries, keep a suppression list, and remove any contact at the first request.

The secondary domain in this construction protects you not from the law, but from operational risk: the technical reputation of the company's main address does not depend on how the market receives your cold emails.

Where the scheme breaks

The typical mistakes that nullify domain separation:

  1. The same text to hundreds of recipients. Mass-sending one identical message is a mailing — to filters, and in the sense of advertising rules. A business email is written to a specific company, not to "everyone in the base."
  2. A link to the main site in the first email. Mailbox systems track the reputation of domains mentioned in the body. The first touch is safer with no links at all.
  3. An empty domain. No site, no redirect — the recipient checks the sender and finds no company.
  4. Starting at full power. Hundreds of emails a day from a rookie domain is the fastest way to kill its reputation before the first reply.
  5. Ignoring opt-outs. Someone asked you not to write — the contact leaves every list immediately. A suppression list is not bureaucracy; it is protection from complaints.

The working scheme: primary untouchable, outreach from the neighbor

Putting it all together in sequence:

Stage What we do
1. Registration Buy a domain that mirrors the brand, in .ru or .com, with a clean history
2. Mail Connect Yandex 360 or Mail.ru for Business (Google Workspace for international targets), create 2–3 mailboxes for real employees
3. DNS Configure SPF, DKIM and DMARC
4. Storefront Redirect to the main site or a page with company details
5. Warm-up Several weeks of low volumes and live correspondence
6. Outreach Targeted business emails, suppression list, reputation monitoring

At OT9 this circuit is part of the standard engagement protocol: base reconnaissance, domain warm-up, the sequence of letters, reply handling, and handoff into your CRM. The client's primary domain never takes part in the operation.

FAQ

Can we get away with a subdomain like mail.company.com?

Not reliably. Mailbox systems tie subdomain reputation to the root domain, so the isolation ends up partial. A separate second-level domain is the clean and predictable solution, and it costs little.

How many domains and mailboxes do we need to start?

In our estimate, one or two domains with two or three mailboxes each is enough for a first operation. Beyond that, the count follows your planned volume: it is better to add a domain than to overload an existing one.

What if the secondary domain gets burned?

That's exactly what the scheme is for: take the domain out of rotation, register a new one, go through warm-up again. Your primary domain and ongoing client correspondence were never touched. Restoring a burned domain's reputation is also possible, but in effort it usually loses to replacement.

Does a secondary domain make cold email legal?

No. Legality is determined by the email's content: a targeted business proposal to a specific company is legitimate; a promotional mailing without the recipient's consent is not — from whichever domain it goes out.

Does this apply if we only email outside Russia?

Yes. The mechanics of domain reputation are the same on Gmail and Outlook as on Yandex and Mail.ru. The local specifics only change which platforms you host the mailboxes on and which receiving-side filters matter most.

If you want a second pair of eyes on your setup, send us your current sequence or a sample target list — we'll run a short teardown of the domain, the technical records and the copy, and tell you plainly what we would fix first: request a teardown.

cold email · deliverability · domain reputation · B2B outbound · Russia market entry

Get your sequence reviewed

Send the current emails and your target list — we return a written teardown.

Send us a sequence for a teardown