in

Cold Emailing Clients as a Freelancer: The Sending Rules That Apply Below 5,000 a Day

A freelancer registers a fresh domain on Monday, sets up an inbox, and starts sending 40 pitches a day to prospects. By Friday nothing has bounced and nothing has been answered, which looks like a copywriting problem. It is usually a delivery problem. Gmail has required SPF or DKIM authentication, valid forward and reverse DNS, a TLS connection and a spam rate under 0.3% from every sender, at any volume, since 1 February 2024. The 5,000-a-day figure quoted in nearly every article on this subject is the line where extra obligations begin, not the line where the rules start applying to you.

Two tiers, and you are in the first one

Google’s email sender guidelines split into “requirements for all senders” and “requirements for sending 5,000 or more messages per day”. Solo freelancers read the second heading, do the arithmetic, and stop reading. The first heading is the one that governs a 40-a-day cold outreach habit.

Hosting 75% off

Requirements that apply to you regardless of volume:

  • SPF or DKIM set up for your sending domain.
  • Valid forward and reverse DNS records, meaning the sending IP resolves to a hostname via a PTR record and that hostname resolves back to the same IP.
  • A TLS connection for transmitting mail.
  • Spam rate below 0.3% as reported in Postmaster Tools.
  • Messages formatted to the RFC 5322 standard, including a valid Message-ID and single-instance headers appearing only once.
  • No impersonation of Gmail From: headers.

Google’s guidance on spam rate goes further than the requirement. It advises keeping the figure below 0.10% and never letting it reach 0.30%, because the impact on delivery is graduated and even rates above 0.1% already hurt.

The Workspace exception that changes the picture

Here is the nuance almost no guide mentions. Google’s sender guidelines apply to mail sent to personal Gmail accounts, meaning addresses ending in @gmail.com or @googlemail.com. Google’s sender guidelines FAQ states plainly that the requirements do not apply to messages sent to Google Workspace accounts.

If you pitch businesses, most of your prospects sit on Workspace, not personal Gmail. That does not make you safe, because Workspace inboxes still run spam filtering and still form a reputation view of your domain. It does mean the specific compliance regime you have been reading about is aimed at a slice of your list rather than all of it. Build for the strict standard anyway; the cost is one afternoon of DNS work and the alternative is guessing.

What the tier above 5,000 adds

Should your sending ever scale, the additional obligations are SPF and DKIM and DMARC, with an enforcement policy that may be set to none; DMARC alignment, meaning the From: header domain must align with either the SPF or DKIM domain for direct mail; and one-click unsubscribe on marketing and subscribed messages, implemented with List-Unsubscribe headers per RFC 8058. A mailto link or an unsubscribe link in the message body does not satisfy that requirement on its own.

One detail deserves its own sentence: bulk sender status, once assigned, is permanent. Google’s FAQ states that senders meeting the 5,000 threshold even once are permanently classified as bulk senders, and that changing your sending practices afterwards will not remove the classification. A single enthusiastic launch campaign therefore signs you up to the stricter regime for good.

Outlook runs a separate regime

Microsoft introduced its own requirements for high-volume senders to Outlook consumer domains, effective 5 May 2025, requiring SPF, DKIM and DMARC for domains sending more than 5,000 messages a day, with non-compliant mail liable to be filtered or blocked. The details are in Microsoft’s announcement for high-volume senders. Passing Gmail’s checks does not automatically satisfy Microsoft’s, and outlook.com and hotmail.com addresses are still common among small business owners.

Read the rejection code instead of guessing

Google publishes the exact error codes attached to each failure, which turns a vague deliverability worry into a specific fix:

  • 4.7.23 and 5.7.25: missing or mismatched PTR record.
  • 4.7.27 and 5.7.27: SPF authentication did not pass.
  • 4.7.29 and 5.7.29: no TLS connection.
  • 4.7.30 and 5.7.30: DKIM authentication did not pass.
  • 4.7.31: no DMARC record, or no policy specified.
  • 4.7.32: From: header not aligned with the authenticated SPF or DKIM domain.
  • 4.7.28: quota exceeded. Google’s advice is to stop sending for at least 10 minutes, then resume from a single connection and add connections one at a time.

Codes beginning 4 are temporary; codes beginning 5 are permanent. Google began ramping up enforcement on non-compliant traffic in November 2025, with disruptions including both temporary and permanent rejections, so the difference is worth knowing.

Why “nobody opened it” proves nothing

Open-rate dashboards are the usual evidence freelancers cite when diagnosing outreach. Google states directly that it does not track open rates, cannot verify third-party open-rate figures, and that low open rates are not necessarily an accurate indicator of deliverability or spam classification problems. Tracking pixels get blocked, and image proxying distorts what is left.

The signal that is real is your spam rate and domain reputation in Postmaster Tools, calculated and updated daily, plus the compliance status dashboard Google added to it. If you are sending pitches at any regularity, verify your domain there before you rewrite a single subject line.

Practices that quietly wreck a new domain

Google’s sending guidance names several habits common in cold outreach. Do not purchase email addresses from other companies. Do not send to people who never signed up. Increase volume gradually rather than in bursts, since sudden spikes from a domain with no sending history invite rate limiting. Use a DKIM key of at least 1024 bits, with 2048 recommended.

The display-name rules are stricter than most people assume. Display names should identify the sender only. Google specifically calls out names that include subject or message content, names containing the recipient’s own name, and names formatted to imply a threaded reply such as “User (2)”. Several popular personalisation tactics land squarely on that list.

A setup order that avoids most of this

  1. Buy a separate domain for outreach so a reputation problem never touches your main site.
  2. Publish SPF and DKIM, then DMARC, before the first send.
  3. Confirm PTR records resolve correctly and TLS is enforced.
  4. Register the domain in Postmaster Tools so you have data from day one.
  5. Start at a handful of messages a day to a hand-built list and increase slowly.
  6. Check spam rate weekly and treat anything approaching 0.1% as a stop signal.

Deliverability work has a poor return on attention right up until the moment it is the only thing standing between you and a reply. It pairs badly with volume and well with precision, which is the same lesson that shows up in writing proposals that actually get replies. Fewer, better-targeted messages keep spam complaints near zero, and near zero is the number the whole system is built around.

Once a cold pitch does convert, the economics change fast, which is why turning that first project into recurring work through a retainer agreement beats sending another hundred emails. Price it against the framework in our guide to calculating your freelance rates.

Rules on unsolicited commercial email vary by country. Check the requirements that apply where you and your recipients are based.

Hosting 75% off

Written by Hajra Naz

Fiverr Level Requirements in 2026: The Official Numbers, Not the Ones on Blogs

The Startup Trying to Fix AI’s Most Expensive Problem Just Secured $100M

The Startup Trying to Fix AI’s Most Expensive Problem Just Secured $100M