The cold email infrastructure build of the last four years had two moves in it. Buy more sending domains than you need, and warm them with a pool so they look established before the first real campaign goes out. In the space of eleven days in September, both moves stopped being clever and started being evidence against you.
On September 3, 2026, Validity launched Heatwave, a public blocklist built specifically to catch domains that manufacture sender reputation through artificial warming. By September 10 it carried 1,052,595 domains, with 6,981 added in the previous twenty four hours. Eleven days after launch, Microsoft began rolling out tenant sending quotas scaled to how old the tenant is. One change punishes the warmup pool. The other removes the escape route the pool existed to serve.
Most sending estates in B2B outbound were assembled out of exactly these two assumptions. That is the problem worth a meeting this week.
Read the fourth figure next to the first three. A blocklist that grows by seven thousand domains a day and never ages anything off is not a filter you wait out. It is a permanent register, and the thing it registers is a practice that a large share of the outbound industry currently sells as a standard service.
What the email warmup blocklist actually lists
The email warmup blocklist lists sending domains rather than IP addresses, and the behaviour it looks for is reciprocal engagement between controlled mailboxes: automated messages that are opened, clicked and replied to by accounts in the same network to make a young domain look trusted.
That distinction matters because it is not a volume rule or a complaint rule. A domain can sit well under every published threshold, pass SPF, DKIM and DMARC cleanly, carry no complaints at all, and still be listed, because the signal being measured is the shape of the engagement rather than the outcome of it. Real recipients do not open every message within the same forty minute window and reply to a quarter of them in a pattern that repeats daily across two hundred mailboxes.
Validity describes the practice as exchanges that manufacture engagement through controlled accounts, including simulated opens, clicks and replies. The detection runs on signals from its own intelligence network, and the list is mirrored into the DNS reputation zones Validity already operates, which is why it reached consumers quickly. Comcast, Proofpoint, Spamhaus, SURBL and beehiiv were named as using or evaluating it at launch. Anyone can check a domain at Validity's public lookup.
| WHAT GETS OBSERVED | HOW THE DOMAIN IS RECORDED | WHAT IT MEANS IN PRACTICE |
|---|---|---|
| Synthetic warming traffic only | Listed on the warming signal alone, before any campaign has been sent | A domain can be listed while it is still parked. Nothing has reached a prospect yet and the record already exists |
| Warming followed by live outreach | The record is updated to reflect active outbound sending from a previously warmed domain | This is the category most agency estates fall into, because warming before launch is the default build |
| A sibling domain in a known warming family | Listed in an advisory capacity before any sending at all is observed from it | Registration pattern alone is enough. Buying forty lookalike domains on one card now creates forty records, not one |
| Behaviour stops after listing | The listing remains. Warming observations do not expire and are not cleared by stopping | There is no quiet waiting period. The remediation most teams would reach for first does not exist here |
| Misattribution, impersonation or compromise | Removable through formal review, typically inside two to five business days | The only exit is proving the classification was wrong, which is not the same as proving you have reformed |
The third row is the one that breaks the planning model. A domain that has never sent a message can be listed because of the company it was registered with. Bulk registration of lookalike domains, which is the first step in almost every scaled outbound build, is itself a detectable pattern now.
Why stage based listing breaks the domain rotation hedge
Domain rotation worked as a hedge because reputation damage was contained: a burned domain was retired, a fresh one replaced it, and the loss stopped at the boundary of the retired name. Listing by registration family removes that containment and turns the portfolio into one correlated position.
Run the arithmetic on a standard build. Forty sending domains, three mailboxes each, all registered in one session at one registrar on one card, all pointed at variations of the same brand, all warmed through the same pool before launch. Under the old model that is one hundred and twenty mailboxes of resilience. Under a register that lists siblings by family, it is one exposure with one hundred and twenty surface points, and the thing that correlates them is not their sending behaviour but their purchase receipt.
This is the opposite of what the estate was built to achieve, and it is worth being precise about the reversal. Rotation was always a bet that identity is cheap and reputation is disposable. The counter argument, which we made when the private networks versus more domains debate was still a live argument among practitioners, is that every disposable identity you add is another thing a provider can learn to recognise as disposable. That is now the documented mechanism rather than a prediction.
“A hedge only works when the positions are independent. Forty domains bought in one session and warmed in one pool were never independent. They just had not been correlated out loud before.”
There is a second order effect on agencies specifically. A pool is a shared network by construction, which means your client's domains were warmed against other people's domains, and the family signal does not stop at the edge of your account. Agencies running a shared warmup pool across a book of clients have, without intending to, built one reputational object out of the entire book. Any audit of this should start with a deliverability audit of the warmup pool itself rather than with individual domain health.
Microsoft closed the other exit eleven days later
Microsoft began rolling out tiered Tenant External Recipient Rate Limit quotas on September 14, 2026, scaling how many external recipients a tenant may reach per day to the age of the tenant itself rather than to the number of licences purchased.
The obvious response to a listed domain estate is to rebuild it somewhere clean. These quotas price that response out. A brand new tenant is throttled hard, and the throttle lifts on a calendar rather than on spend, so capacity cannot be bought forward. Trial tenants are capped at 500 external recipients a day regardless of licence count, which closes the cheapest version of the workaround completely.
Microsoft tenant external recipient quota as a share of the standard allowance, by tenant age, from the tiered limits Microsoft began rolling out on September 14, 2026
Sixty days to full capacity is the number to plan against. It is also, read the other way, the clearest statement any provider has made that tenant age is now a first class reputation input. You cannot warm your way past it, because the quota is not responsive to behaviour at all. It responds only to the calendar, which is the one input a warmup pool was invented to fake.
Both changes point the same direction, and that convergence is the real signal. We argued the case for slower domain aging and a real ramp schedule on reputation grounds when it was still a matter of judgement. It is now partly a hard quota, enforced by the platform, with no appeal and no configuration flag.
Visibility is moving the other way at the same time, which is worth noting while you plan. Gmail's Postmaster Tools API v2 does not carry the Domain and IP Reputation fields the legacy interface exposed, so the monitoring surface is thinning just as the enforcement surface thickens. Build your measurement on what you can observe directly, which is placement and reply behaviour, rather than on vendor reputation scores that may not survive the next deprecation. The same reasoning applies to how you read hard bounces against soft bounces when a provider starts rejecting outright instead of foldering.
What the email warmup blocklist means for an estate you already built
An estate built before September needs triage rather than reconstruction, and the first job is factual: find out which of your domains are listed today, because the answer determines whether you are managing a reputation problem or a disclosure problem.
Check the portfolio against the public lookup before you change anything. The result splits your estate into categories that call for genuinely different responses, and the most expensive mistake available right now is treating all of them as one.
| WHAT YOU FIND | WHAT IT ACTUALLY TELLS YOU | THE MOVE THIS WEEK |
|---|---|---|
| Listed domains currently carrying live campaigns | Active sending from a domain on a register shared with major filtering vendors | Stop sending from them. Move the sequences to your oldest unlisted domains and accept the volume reduction while you rebuild |
| Listed domains that never sent anything | The warming signal or the registration family was enough on its own | Do not warm them and do not launch them. They are already spent. Write off the registration cost rather than the sending reputation |
| Unlisted domains that went through the same pool | Timing, not safety. The same behaviour was observed on their siblings | Treat as listed in your planning. Stop all pool activity on them today so the record does not extend |
| Your primary corporate domain, if it was ever pooled | The highest severity finding available. Invoices, support and contracts share this reputation | Escalate immediately. Nothing in outbound is worth a listing on the domain the business runs on |
| A listing you believe is wrong | Possible misattribution, impersonation, compromise or confusion between similar domains | File for review with evidence. This is the only removal path and it takes roughly two to five business days |
The fourth row deserves more alarm than it usually gets. Plenty of small teams warmed their real company domain early on because it was the one they had, and the exposure there is not a dip in reply rate. It is finance and support mail from the domain the company actually runs on, sitting behind the same signal, shared with vendors like Proofpoint that sit in front of enterprise inboxes.
Before anyone proposes a fix, get the question in front of the right people. Validity's own guidance to senders is to check related domains and ask sales, marketing and outside vendors what is running in the company's name before assuming an error, which is a polite way of saying that the warmup nobody told you about is usually real.
How to build sending capacity without a warmup pool
Sending capacity without synthetic warming is built on real recipients, patience and a smaller estate, and the good news in the arithmetic is that a correctly sized estate was always cheaper than the one most teams run.
The replacement is not a different tool. It is a different shape of programme, and it is the one that survives both September changes without modification.
There is a cost to say out loud. A team sending from forty pooled domains cannot replicate that volume from six aged domains, and anyone claiming otherwise is selling something. Volume comes down, probably by a lot, and the programme has to earn its number back through relevance rather than through reach. That is a worse quarter and a better business, and the alternative is a permanent record held by the vendors who gate enterprise mail.
Questions teams are asking about the email warmup blocklist
See where you are cited today
A free snapshot audit of your rankings and AI citations before we ever talk.
Tyler leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.