Something Inc.LoginSchedule a free consultation
STRATEGY

The Email Warmup Blocklist Ends Domain Rotation

Validity listed more than a million domains for synthetic warming, then Microsoft tied sending quotas to tenant age eleven days later. The two changes together retire the standard cold email infrastructure build.

STRATEGYCOLD EMAILOCT 2026

The cold email infrastructure build of the last four years had two moves in it. Buy more sending domains than you need, and warm them with a pool so they look established before the first real campaign goes out. In the space of eleven days in September, both moves stopped being clever and started being evidence against you.

On September 3, 2026, Validity launched Heatwave, a public blocklist built specifically to catch domains that manufacture sender reputation through artificial warming. By September 10 it carried 1,052,595 domains, with 6,981 added in the previous twenty four hours. Eleven days after launch, Microsoft began rolling out tenant sending quotas scaled to how old the tenant is. One change punishes the warmup pool. The other removes the escape route the pool existed to serve.

Most sending estates in B2B outbound were assembled out of exactly these two assumptions. That is the problem worth a meeting this week.

SEP 3
the date Validity launched the Heatwave blocklist, built to identify domains using synthetic warming, fake engagement and manufactured sender reputation
1,052,595
domains listed as of September 10, one week after launch, a figure Validity publishes through its own lookup service rather than an outside estimate
6,981
domains added in a single twenty four hour period that week, which is the growth rate that matters more than the opening total
NEVER
how often a warming listing expires. Stopping the behaviour does not clear the record, and removal requires a formal review finding that the original classification was wrong

Read the fourth figure next to the first three. A blocklist that grows by seven thousand domains a day and never ages anything off is not a filter you wait out. It is a permanent register, and the thing it registers is a practice that a large share of the outbound industry currently sells as a standard service.

What the email warmup blocklist actually lists

The email warmup blocklist lists sending domains rather than IP addresses, and the behaviour it looks for is reciprocal engagement between controlled mailboxes: automated messages that are opened, clicked and replied to by accounts in the same network to make a young domain look trusted.

That distinction matters because it is not a volume rule or a complaint rule. A domain can sit well under every published threshold, pass SPF, DKIM and DMARC cleanly, carry no complaints at all, and still be listed, because the signal being measured is the shape of the engagement rather than the outcome of it. Real recipients do not open every message within the same forty minute window and reply to a quarter of them in a pattern that repeats daily across two hundred mailboxes.

Validity describes the practice as exchanges that manufacture engagement through controlled accounts, including simulated opens, clicks and replies. The detection runs on signals from its own intelligence network, and the list is mirrored into the DNS reputation zones Validity already operates, which is why it reached consumers quickly. Comcast, Proofpoint, Spamhaus, SURBL and beehiiv were named as using or evaluating it at launch. Anyone can check a domain at Validity's public lookup.

WHAT GETS OBSERVEDHOW THE DOMAIN IS RECORDEDWHAT IT MEANS IN PRACTICE
Synthetic warming traffic onlyListed on the warming signal alone, before any campaign has been sentA domain can be listed while it is still parked. Nothing has reached a prospect yet and the record already exists
Warming followed by live outreachThe record is updated to reflect active outbound sending from a previously warmed domainThis is the category most agency estates fall into, because warming before launch is the default build
A sibling domain in a known warming familyListed in an advisory capacity before any sending at all is observed from itRegistration pattern alone is enough. Buying forty lookalike domains on one card now creates forty records, not one
Behaviour stops after listingThe listing remains. Warming observations do not expire and are not cleared by stoppingThere is no quiet waiting period. The remediation most teams would reach for first does not exist here
Misattribution, impersonation or compromiseRemovable through formal review, typically inside two to five business daysThe only exit is proving the classification was wrong, which is not the same as proving you have reformed

The third row is the one that breaks the planning model. A domain that has never sent a message can be listed because of the company it was registered with. Bulk registration of lookalike domains, which is the first step in almost every scaled outbound build, is itself a detectable pattern now.

THE VERDICTTreat this as a permanent public record keyed to your domain portfolio, not as a spam filter you can tune around. Filters forgive. Registers do not. The practical consequence is that every domain you warm artificially from here is a sunk asset the moment you warm it.

Why stage based listing breaks the domain rotation hedge

Domain rotation worked as a hedge because reputation damage was contained: a burned domain was retired, a fresh one replaced it, and the loss stopped at the boundary of the retired name. Listing by registration family removes that containment and turns the portfolio into one correlated position.

Run the arithmetic on a standard build. Forty sending domains, three mailboxes each, all registered in one session at one registrar on one card, all pointed at variations of the same brand, all warmed through the same pool before launch. Under the old model that is one hundred and twenty mailboxes of resilience. Under a register that lists siblings by family, it is one exposure with one hundred and twenty surface points, and the thing that correlates them is not their sending behaviour but their purchase receipt.

This is the opposite of what the estate was built to achieve, and it is worth being precise about the reversal. Rotation was always a bet that identity is cheap and reputation is disposable. The counter argument, which we made when the private networks versus more domains debate was still a live argument among practitioners, is that every disposable identity you add is another thing a provider can learn to recognise as disposable. That is now the documented mechanism rather than a prediction.

“A hedge only works when the positions are independent. Forty domains bought in one session and warmed in one pool were never independent. They just had not been correlated out loud before.”

There is a second order effect on agencies specifically. A pool is a shared network by construction, which means your client's domains were warmed against other people's domains, and the family signal does not stop at the edge of your account. Agencies running a shared warmup pool across a book of clients have, without intending to, built one reputational object out of the entire book. Any audit of this should start with a deliverability audit of the warmup pool itself rather than with individual domain health.

Microsoft closed the other exit eleven days later

Microsoft began rolling out tiered Tenant External Recipient Rate Limit quotas on September 14, 2026, scaling how many external recipients a tenant may reach per day to the age of the tenant itself rather than to the number of licences purchased.

The obvious response to a listed domain estate is to rebuild it somewhere clean. These quotas price that response out. A brand new tenant is throttled hard, and the throttle lifts on a calendar rather than on spend, so capacity cannot be bought forward. Trial tenants are capped at 500 external recipients a day regardless of licence count, which closes the cheapest version of the workaround completely.

Non-trial tenant, under 31 days old: 10% of standard quota10%
Non-trial tenant, 31 to 60 days old: 25% of standard quota25%
Non-trial tenant, over 60 days old: 100% of standard quota100%

Microsoft tenant external recipient quota as a share of the standard allowance, by tenant age, from the tiered limits Microsoft began rolling out on September 14, 2026

Sixty days to full capacity is the number to plan against. It is also, read the other way, the clearest statement any provider has made that tenant age is now a first class reputation input. You cannot warm your way past it, because the quota is not responsive to behaviour at all. It responds only to the calendar, which is the one input a warmup pool was invented to fake.

Both changes point the same direction, and that convergence is the real signal. We argued the case for slower domain aging and a real ramp schedule on reputation grounds when it was still a matter of judgement. It is now partly a hard quota, enforced by the platform, with no appeal and no configuration flag.

Visibility is moving the other way at the same time, which is worth noting while you plan. Gmail's Postmaster Tools API v2 does not carry the Domain and IP Reputation fields the legacy interface exposed, so the monitoring surface is thinning just as the enforcement surface thickens. Build your measurement on what you can observe directly, which is placement and reply behaviour, rather than on vendor reputation scores that may not survive the next deprecation. The same reasoning applies to how you read hard bounces against soft bounces when a provider starts rejecting outright instead of foldering.

What the email warmup blocklist means for an estate you already built

An estate built before September needs triage rather than reconstruction, and the first job is factual: find out which of your domains are listed today, because the answer determines whether you are managing a reputation problem or a disclosure problem.

Check the portfolio against the public lookup before you change anything. The result splits your estate into categories that call for genuinely different responses, and the most expensive mistake available right now is treating all of them as one.

WHAT YOU FINDWHAT IT ACTUALLY TELLS YOUTHE MOVE THIS WEEK
Listed domains currently carrying live campaignsActive sending from a domain on a register shared with major filtering vendorsStop sending from them. Move the sequences to your oldest unlisted domains and accept the volume reduction while you rebuild
Listed domains that never sent anythingThe warming signal or the registration family was enough on its ownDo not warm them and do not launch them. They are already spent. Write off the registration cost rather than the sending reputation
Unlisted domains that went through the same poolTiming, not safety. The same behaviour was observed on their siblingsTreat as listed in your planning. Stop all pool activity on them today so the record does not extend
Your primary corporate domain, if it was ever pooledThe highest severity finding available. Invoices, support and contracts share this reputationEscalate immediately. Nothing in outbound is worth a listing on the domain the business runs on
A listing you believe is wrongPossible misattribution, impersonation, compromise or confusion between similar domainsFile for review with evidence. This is the only removal path and it takes roughly two to five business days

The fourth row deserves more alarm than it usually gets. Plenty of small teams warmed their real company domain early on because it was the one they had, and the exposure there is not a dip in reply rate. It is finance and support mail from the domain the company actually runs on, sitting behind the same signal, shared with vendors like Proofpoint that sit in front of enterprise inboxes.

Before anyone proposes a fix, get the question in front of the right people. Validity's own guidance to senders is to check related domains and ask sales, marketing and outside vendors what is running in the company's name before assuming an error, which is a polite way of saying that the warmup nobody told you about is usually real.

How to build sending capacity without a warmup pool

Sending capacity without synthetic warming is built on real recipients, patience and a smaller estate, and the good news in the arithmetic is that a correctly sized estate was always cheaper than the one most teams run.

The replacement is not a different tool. It is a different shape of programme, and it is the one that survives both September changes without modification.

01Shrink the estate before you age itConsolidate onto the smallest number of domains that can carry your real volume at a defensible per mailbox rate. Fewer domains sending more each is now the lower risk configuration, which inverts the advice of the last four years. Every domain you keep is a record you maintain.
02Warm with real recipients onlyStart with people who have a reason to reply: existing customers, partners, inbound leads, event contacts, recruiting conversations. Low volume, genuine threads, no automation on the response side. Slower than a pool and it produces engagement that no behavioural model can distinguish from legitimate, because it is.
03Age tenants ahead of demandTenant age is now a quota input, so provision capacity sixty days before you need it rather than in the week the campaign is approved. Treat new tenants as a lead time item on the roadmap in the same way you would treat a hiring plan.
04Make list quality carry the loadCapacity that used to come from more mailboxes now has to come from fewer wasted sends. Tighter targeting, verified addresses and a shorter sequence put less pressure on an estate you can no longer grow on demand. This is where our cold email engagements spend the first month, and it is the only input in the system that still scales freely.

There is a cost to say out loud. A team sending from forty pooled domains cannot replicate that volume from six aged domains, and anyone claiming otherwise is selling something. Volume comes down, probably by a lot, and the programme has to earn its number back through relevance rather than through reach. That is a worse quarter and a better business, and the alternative is a permanent record held by the vendors who gate enterprise mail.

Questions teams are asking about the email warmup blocklist

What is the Heatwave blocklist?A public blocklist Validity launched on September 3, 2026 that lists sending domains observed manufacturing sender reputation through synthetic warming: automated opens, clicks and replies exchanged between controlled mailboxes.
How do I check whether my domain is listed?Query the domain at Validity's public lookup service. Check every domain in the portfolio, not just the ones currently sending, because domains can be listed before any campaign has run.
Does a listing expire if I stop using a warmup pool?No. Warming listings do not expire and stopping the behaviour does not clear one. Removal requires a formal review finding that the classification was wrong.
Can a domain be listed before it has sent anything?Yes. A domain registered as part of a known warming family can be listed in an advisory capacity before any sending is observed, which makes bulk lookalike registration a detectable pattern on its own.
Who actually uses this list?Validity named Comcast, Proofpoint, Spamhaus, SURBL and beehiiv as using or evaluating it at launch, and it is mirrored into Validity's existing DNS reputation zones, so consumption is easy for anyone already querying those.
What changed with Microsoft sending limits?From September 14, 2026 Microsoft began scaling tenant external recipient quotas to tenant age: 10% of standard under 31 days, 25% at 31 to 60 days, 100% after 60 days, and 500 per day for trial tenants.
Can I buy my way to full sending capacity on a new tenant?No. The quota tiers track tenant age rather than licence count, and trial tenants are capped at 500 external recipients a day regardless of how many licences are attached.
Is all warmup now a problem?No. Gradually increasing real sending to real recipients is legitimate and always was. What is being listed is manufactured engagement between controlled accounts, which is a different practice that happens to share a name.
How long does a removal request take?Roughly two to five business days once filed, but only on grounds of misattribution, impersonation, compromise or confusion between domains. Reform is not a listed ground for removal.
What is the first thing to do today?Audit the portfolio against the lookup, stop all pool activity immediately so no further records accrue, and check whether your primary corporate domain was ever warmed. That last one is the finding that cannot wait.
DO THIS NEXTPull the full list of domains the business owns, including the ones marketing and outside vendors registered, and check every one against the public lookup today. Then stop every warmup pool you are paying for, because each additional day of it extends a record that nothing you do later will clear. Rebuild capacity on aged tenants and real recipients, and plan sixty days ahead of the campaign that needs it.

See where you are cited today

A free snapshot audit of your rankings and AI citations before we ever talk.

TT
Tyler TruffiMANAGING PARTNER, SOMETHING INC.

Tyler leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.

Free consultation

Let us be the last SEO agency you ever work with

A 30 minute call and a free audit of your SEO and GEO position. You keep the findings either way.