LeadlistVerifier

Cold Email Bounce Rate: What's Normal, What's Not

Jeremy Dixon, Founder of Elevate Clients Inc.9 min read

In short

Cold outreach conventionally aims for a bounce rate under 2 percent, with 5 percent treated as a stop signal. Variance between campaigns is driven mostly by how the list was sourced, how old it is, and how the catch-all segment was handled.

I run cold email for a living at Elevate Clients Inc., a B2B agency, and the question I get asked most about deliverability is some version of: is this normal? Usually about a bounce rate that has just come back higher than expected, usually after a campaign has already started.

This article is about where the accepted thresholds come from, why two campaigns from the same team can land far apart, and what to check before a launch rather than after one.

What counts as a bounce

A bounce is a message a receiving server refused. In cold outreach the number that matters is the hard bounce rate specifically: the share of attempted sends rejected because the mailbox does not exist or the domain cannot receive mail at all. Those are permanent refusals, and they are the ones providers read as a signal about the sender.

Two measurement details change the figure enough to matter. Count against messages actually attempted rather than against the size of the file you imported, since addresses removed before sending never had the chance to bounce and including them flatters the result. And separate hard from soft, because a mailbox that is temporarily full tells you nothing about list quality while a mailbox that does not exist tells you everything.

The bounces that arrive late

One thing catches operators out repeatedly, and it is worth knowing before it happens to you. Not every rejection arrives during the send.

A server that accepts a message has not necessarily delivered it. It has taken responsibility for trying. If the internal routing then fails, because the mailbox does not exist behind an accept-everything configuration, the rejection comes back as an asynchronous notification some time later. Hours later is common, and the following day is not unusual.

The practical consequence is that a bounce rate read an hour after launch is provisional. A campaign heavy in unresolved catch-all addresses can look clean at the point you decide to scale it, then drift upward through the evening as the delayed notifications land. Teams that scale on the early number rather than the settled one end up committing volume to a list that was already failing. Read the figure the next morning before making decisions with it.

The thresholds, and where they come from

The convention is under 2 percent for cold outreach, with sustained rates above 5 percent treated as a reason to pause rather than optimise. Permission-based sending to an engaged list should sit well under half a percent.

It is worth being precise about the provenance, because these numbers get quoted as though they were published specifications. They are not. Mailbox providers do not disclose the thresholds at which their filtering changes behaviour, and they would be unwise to, since publishing them would tell every spam operation exactly how close to the line it could sit. The figures in circulation are inferred from observed outcomes across many senders and have hardened into working rules.

Treat them as a warning line rather than a limit. Sitting at 1.9 percent deliberately is not a strategy, it is a bet that the inference is precise. A well-verified cold list should come in comfortably below the convention rather than just under it, and if yours is hovering near the line the list is telling you something.

Why cold email bounces more than marketing email

Comparing the two is the most common source of unnecessary alarm. They are different activities with different data.

A marketing list is self-validating. Someone typed their own address into a form, and in most cases confirmed it by clicking a link in a message that arrived. The list then refreshes itself continuously, because engagement tells you which addresses are still live and unsubscribes remove the ones that are not.

A cold list has none of those properties. It is assembled from third-party data about people who never gave you anything, so no human has confirmed any address is correct, and no ongoing signal tells you when one stops being correct. Verification is the only mechanism available that substitutes for the confirmation step a marketing list gets for free. That is the whole reason it matters more here.

What actually drives the variance

Two campaigns run by the same team in the same month can land far apart. In my experience the spread is almost entirely explained by four things, in roughly this order of impact.

How the list was sourced

This dominates everything else. Addresses that were pattern-generated from a name and a domain, the first.last@company.com approach, are guesses, and a meaningful share are wrong by construction. Addresses from a reputable provider that verifies before selling are better. Addresses from a provider that scraped and never checked are worse than guessing, because they carry the appearance of provenance.

There is a third tier worth naming, because it gets conflated with cold data and behaves nothing like it. Addresses collected through your own channels, an event registration, a content download, an enquiry form, have been typed by the person who owns them. They belong in a separate list with separate expectations, and mixing them into a cold file hides their quality inside an average that describes neither group.

How old it is

Decay is continuous and invisible until you send. A file collected twelve months ago and never re-checked carries materially more dead addresses than the same file did on the day it was assembled, and nothing about the file looks different. This is the factor teams consistently underweight, because the list was clean when they got it and nobody watched it stop being clean.

What vertical you are selling into

Turnover rates differ sharply by industry, and turnover is what drives decay. Sectors with high churn in the roles you target will degrade a list faster than sectors where people stay for years. Company size matters too, in the opposite direction from what people expect: larger organisations are more likely to keep a departed employee’s address alive and forwarding, which reads as deliverable while reaching the wrong person.

What you did with the catch-all segment

This is the one that produces the widest spread between otherwise similar campaigns, and it is the least discussed. On a typical B2B list, 25 to 30 percent of addresses sit on domains that accept mail for everything. What you do with that quarter sets both your bounce rate and how much of the list you can actually use, and the three available choices produce very different outcomes.

The same list, three ways

Take a 10,000-address B2B list. A standard verification pass settles about 7,500 addresses cleanly and returns 2,500 as catch-all. From there:

  • Delete the 2,500. Your bounce rate will look excellent, because you removed a quarter of the list including all the addresses that were fine. You bought and verified contacts in order to throw them away.
  • Send to all 2,500 unverified. Your bounce rate becomes a lottery. Some of those mailboxes do not exist and you have no way to know which, and because catch-all servers accept first and decide later, some of the damage arrives as delayed bounces after the campaign looks finished.
  • Resolve the segment first. A second verification pass returns a definitive verdict for roughly 72 percent of it, about 1,800 addresses, which is 18 percent of the whole list moving from unusable to confidently sendable. Bounce rate stays low because you are sending to confirmed mailboxes rather than hoping.

Only the third option gets both numbers right at once, and the gap between the first and third is the difference between a 7,500-address campaign and a 9,300-address one from the same purchase.

Keeping it under the line

Four levers control the number, and they are covered properly in the guide to reducing bounce rate. In summary: verify the list before sending and re-verify before each campaign; get SPF, DKIM and DMARC correct on dedicated sending domains; warm new domains gradually rather than launching into volume; and maintain suppression lists so removed addresses cannot return through a later import.

Verification is the lever that moves the number most, because invalid addresses are the direct cause of hard bounces and everything else is a second-order effect. How verification works covers the mechanics, and the two-pass engine covers what happens to the segment a standard pass leaves behind.

A pre-launch checklist

This is the sequence I actually run before a campaign goes out, in order.

  1. Verify the file, not a sample of it. Sampling tells you the shape of the list. It does not remove the dead addresses from the part you did not sample.
  2. Read the catch-all share before anything else. It predicts your usable volume and tells you whether the segment needs resolving or is small enough to ignore.
  3. Segment rather than merge. Confirmed deliverable in one list, resolved catch-alls in another, risky held back. If a problem appears mid-campaign you want to know which group it came from.
  4. Check the suppression list applied. The most common cause of a bounce rate creeping back up is an old file appended to a clean one, restoring addresses you already proved were dead.
  5. Confirm authentication on every sending domain. Not the primary one. Every one, including the domain added last week that nobody re-checked.
  6. Start below your target volume. Send a first day at a fraction of the intended rate and read the bounce figure before committing the rest. A bad list is far cheaper to discover on day one.

If you run this and your numbers land somewhere unexpected, I am genuinely interested to hear it. Real figures from real campaigns are more useful than any benchmark table, and this article will be updated with them rather than with estimates. You can get in touch here. If you want to test the verification step first, a free account includes 100 credits and pricing is credit-based with no subscription.

Frequently asked questions

What is a normal bounce rate for cold email?

The working convention is under 2 percent, with anything sustained above 5 percent treated as a reason to stop rather than adjust. Worth knowing where those figures come from: mailbox providers do not publish the thresholds they act on, so these are inferred from observed behaviour and passed around as rules of thumb. They are a useful warning line and not a specification.

Why does cold email bounce more than marketing email?

Because of how the list was assembled. A marketing list is built from people who typed their own address into a form and confirmed it, which makes it self-validating and continuously refreshed by engagement. A cold list is assembled from third-party data about people who never gave you anything, so nobody has confirmed those addresses are correct and no ongoing signal tells you when they stop being correct.

Does a low bounce rate mean my list is good?

Not by itself. Bounce rate only counts messages a server refused, so mail that is accepted and then discarded never appears in it. Catch-all domains accept everything by design, which means a list heavy in unresolved catch-all addresses can post an excellent bounce rate while a meaningful share of the sends go nowhere. A low bounce rate alongside a weak reply rate is the pattern that gives this away.

How much does list age affect bounce rate?

More than most other factors, and it compounds quietly. Addresses decay continuously as people change roles and mailboxes are closed, so a file collected a year ago and never re-checked carries a materially higher share of dead addresses than the same file did on the day it was built. The decay rate varies by vertical, and it is fastest in industries with high staff turnover.

Should I split my sending across multiple domains?

For cold outreach at any real volume, yes. Reputation attaches to the sending domain, so separating outreach from the domain your customers use to reach you contains the damage when something goes wrong. It also means a problem on one outreach domain does not take your invoices and support replies down with it, which is the failure mode people regret most.

Try it on your own list.

100 free credits on signup, no card required. Or check a single address with the free verifier, no account needed.