Microsoft 365 Cold Email Deliverability: Settings and Limits Guide

Your Microsoft 365 inboxes were sending fine last month. Now replies have dried up, test emails land in Junk, and a few sends are bouncing with throttling errors. This is the frustrating middle ground of Microsoft 365 cold email deliverability, where the mailboxes technically work but the messages stop reaching real people.
Microsoft 365, formerly Office 365, filters cold email more aggressively than most senders expect. Outlook and Exchange Online lean on tenant reputation, SmartScreen signals, and strict sending limits that behave differently from Gmail. Get the setup right and M365 is a reliable cold sending platform. Get it wrong and you burn a domain in weeks.
This guide covers the exact sending limits, authentication records, warm-up numbers, and settings that keep Microsoft 365 outbound in the inbox.
How Microsoft 365 Handles Cold Email Differently From Gmail
Gmail and Microsoft 365 both decide inbox placement on reputation, but they weigh the signals differently. Google leans heavily on domain reputation and engagement data surfaced through Postmaster Tools. Microsoft leans on tenant-level reputation, IP history, and a filtering stack that includes SmartScreen, Exchange Online Protection, and Microsoft Defender for Office 365.
The practical difference is that Microsoft is quieter and less forgiving. There is no equivalent of Postmaster Tools that shows you a clean reputation score for your sending domain. When Microsoft decides you look like a cold sender, it often routes you to Junk silently or throttles you with a 550 error, and you find out from falling reply rates rather than a dashboard.
Microsoft also filters inbound differently for consumer Outlook (outlook.com, hotmail.com, live.com) versus business M365 tenants. Consumer Outlook is notoriously strict on new senders. Business tenants apply their own admin-configured rules and connectors on top of Microsoft's defaults, so two recipients on the same content can see very different placement.
The takeaway: warm-up, authentication, and volume discipline matter more on Microsoft 365, because you get less visibility and fewer second chances.
Microsoft 365 Sending Limits You Must Know
Every Microsoft 365 mailbox runs against fixed sending limits set by Exchange Online. These apply across Business Basic, Business Standard, Business Premium, and the Enterprise E3 and E5 plans. Confirm your exact figures against current Microsoft documentation, since Microsoft adjusts these periodically and some numbers vary by plan and tenant.
| Limit | Standard M365 value | What it means for cold |
|---|---|---|
| Recipient rate limit | 10,000 recipients per day | Total recipients per mailbox in a rolling 24 hours |
| Recipients per message | 500 by default, adjustable up to 1,000 | Combined To, Cc, and Bcc on one message |
| Message rate limit | 30 messages per minute | How fast one mailbox can submit over SMTP |
| Encrypted message recipients | About 200 recipients | Cap for encrypted mail specifically |
| Tenant external recipient limit (TERRL) | Varies by license count | Tenant-wide daily cap on external recipients |
| onmicrosoft.com sending | 100 external recipients per day | Hard throttle on the default domain |
The recipient rate limit resets on a rolling 24-hour window, not at midnight. If a mailbox hits 10,000 recipients at 9:00 AM, it cannot send to external recipients again until 9:00 AM the next day.
The tenant-level limit (TERRL) is newer and trips up teams scaling multiple mailboxes. Microsoft calculates it from your paid license count using a published formula, roughly 500 multiplied by your non-trial license count raised to the power of 0.7, plus 9,500. Trial tenants are capped at 5,000 external recipients per day regardless of licenses. You can find your tenant's exact number in the Exchange admin center under the Mail flow reports.
One important update: Microsoft canceled its planned per-mailbox external recipient limit of 2,000 per day in January 2026, so the tenant-level TERRL is now the external ceiling that matters. For cold sending, none of these technical ceilings should ever be your target. Reputation collapses far below them.
Authentication Setup: SPF, DKIM, DMARC for M365
Microsoft will not trust a cold sender that fails authentication. Three DNS records do the work, and all three must pass and align. Set these up on a custom domain you own, never on the default onmicrosoft.com address.
SPF (TXT record). SPF authorizes Microsoft's servers to send for your domain. The standard Microsoft 365 SPF record is:
`v=spf1 include:spf.protection.outlook.com -all`
Publish one SPF record per domain. If you route through other sending platforms, add their include mechanisms and stay under the 10 DNS lookup limit.
DKIM (CNAME records). DKIM signs each message with a key Microsoft manages. Enable it in the Microsoft Defender portal under the email authentication settings. Microsoft generates two CNAME records (selector1 and selector2) for you to publish in DNS, then you switch DKIM signing on for the domain.
DMARC (TXT record). DMARC tells Outlook what to do when SPF or DKIM fail, and it is where alignment gets enforced. Start with:
`v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com`
Run p=none for two to four weeks while you read the reports, then tighten to p=quarantine and eventually p=reject once you confirm all legitimate mail passes.
The custom domain point is critical. Microsoft throttles the default onmicrosoft.com domain to 100 external recipients per day and gives it no room to build reputation. Every cold mailbox must send from a custom domain with its own SPF, DKIM, and DMARC records. This is also what lets you keep the sender reputation you build, because the domain is yours.
Warming Up Microsoft 365 Inboxes
A brand-new Microsoft 365 mailbox has no sending history, which to Microsoft reads as risk. Warm-up builds that history gradually by sending low volumes of high-engagement mail before you touch a single prospect.
A safe Microsoft 365 warm-up ramp looks like this:
| Week | Sends per mailbox per day |
|---|---|
| Week 1 | 5 to 10 |
| Week 2 | 10 to 20 |
| Week 3 | 20 to 30 |
| Week 4 and beyond | 30 (production ceiling for cold) |
Give every mailbox at least three weeks of warm-up before it sends real campaigns. Microsoft is slower to trust new tenants than Gmail is, so rushing the ramp is the fastest way to land in Junk from day one.
Use an automated warm-up network, built into tools like Smartlead and Instantly, so mailboxes exchange opens, replies, and positive interactions with real inboxes. Keep warm-up running at a low level even after you go live, because Microsoft continuously re-scores sender behavior.
Settings and Habits That Protect Deliverability
Configuration gets you into the inbox. Habits keep you there. A few settings protect Microsoft 365 deliverability more than anything else.
Use dedicated sending domains, not your primary. Register separate domains for cold outbound (variations of your brand work well) and leave your main company domain for real business mail. If a cold domain takes a reputation hit, your core email keeps flowing.
Run multiple mailboxes across multiple domains. A common structure is two to four mailboxes per sending domain, each capped at 30 sends per day. Two or three domains gives you 4 to 12 mailboxes and 120 to 360 daily sends without straining any single mailbox.
Validate every list before you send. Bounces are one of the loudest negative signals to Microsoft. Run each list through a verification tool and keep your bounce rate under 2 to 3 percent. A spike in bounces will drop placement across the whole tenant.
Watch complaint and reply signals. Poor targeting drives spam complaints, and complaints drag reputation down faster than volume ever will. Tighten your ICP before you widen your send.
Keep content plain. Skip heavy HTML, image-only emails, link shorteners, and attachments in cold outbound. Plain, personal text clears Microsoft's filters more reliably.
Microsoft 365 rewards patience and punishes shortcuts. The teams that win treat every mailbox like an asset they are building, not a faucet they can crank open on day one.
Common Microsoft 365 Deliverability Mistakes
Most Microsoft 365 deliverability failures come down to the same handful of mistakes.
Sending from the primary domain. Cold volume on yourcompany.com puts your entire organization's email at risk. One reputation hit and invoices, contracts, and internal mail start landing in Junk.
Skipping warm-up. New mailboxes pushed straight to 50 or 100 sends per day get filtered almost immediately. Microsoft has no history to trust, so it defaults to caution.
Ignoring bounces. Sending to stale or unverified lists spikes your bounce rate, and Microsoft reads high bounces as a spammer signature. Clean the list first, every time.
Sending from onmicrosoft.com. The default domain is throttled to 100 external recipients per day and cannot build reputation. It is fine for internal testing and useless for outbound.
Treating limits as targets. The 10,000 recipient ceiling is a technical maximum, not a goal. Reputation collapses far below it.
Running M365 Outbound as a System
Microsoft 365 deliverability is not a one-time setup. It is a system of domains, mailboxes, authentication, warm-up, list hygiene, and weekly monitoring that has to run continuously. Most in-house teams can build it once but struggle to maintain the discipline week after week.
This is the part we handle. We build the full Microsoft 365 sending infrastructure, register and authenticate the domains, provision and warm the mailboxes, and monitor placement so issues get caught before reply rates fall. It runs as one orchestrated system rather than a stack of disconnected tools.
The ownership model matters. Every domain, mailbox, and unit of sender reputation we build belongs to you. If we ever part ways, you keep the entire outbound engine, warm-up history included. You can see how this plays out in our case studies, and the full scope of what we build and manage on our services page.
We also stand behind the results. Our pilot is free, there are no long contracts, and if we miss the targets we set together, your billing pauses until we fix it.
Ready to run Microsoft 365 outbound that lands in the inbox?
We build, warm, and manage the entire Microsoft 365 sending system, and you own every domain and mailbox we set up. Start with a free pilot and see the placement for yourself before you commit to anything.
Frequently Asked Questions
A strong positive reply rate for B2B cold email is 1.5–3%. Top-performing campaigns with tight targeting and personalized copy can hit 4–5%. If you're below 1%, it usually signals a deliverability or messaging problem — not a volume problem.
The safe range is 30–50 emails per inbox per day for warmed inboxes. That's why outbound systems use multiple inboxes (we use 80) — to reach 40,000+ monthly sends while keeping each inbox well within safe limits. Sending more than 50/day from a single inbox risks spam folder placement.
Yes. The CAN-SPAM Act permits unsolicited commercial email as long as you include a physical address, an unsubscribe mechanism, accurate headers, and non-deceptive subject lines. Unlike GDPR in Europe, the US does not require prior opt-in consent for B2B cold outreach.
Domain warm-up typically takes 2–3 weeks. During this period, sending volume gradually increases while the email warm-up tool generates positive engagement signals (opens, replies) to build sender reputation. Skipping or rushing warm-up is the most common cause of deliverability problems.
Cold email is targeted, relevant outreach to a specific person based on their role, industry, or company — with a clear business reason. Spam is untargeted mass messaging with no personalization or relevance. The distinction matters legally (CAN-SPAM compliance) and practically (deliverability depends on relevance signals).

Dimitar Petkov
Co-Founder of LeadHaste. Builds outbound systems that compound. 4x founder, Smartlead Certified Partner, Clay Solutions Partner.


