SMTP for Cold Email: Mailbox, Relay or Self-Hosted
Which SMTP works for cold email: mailbox SMTP, relays like SendGrid and Amazon SES, or your own server. What their terms say and how to connect SMTP/IMAP.

On this page
For cold email, use mailbox SMTP: a real mailbox on your own domain that sends over SMTP, receives replies over IMAP and can be warmed up. Transactional and marketing relays such as SendGrid, Amazon SES, Mailgun, Postmark and Brevo are the wrong tool: their terms require recipient consent or forbid purchased and scraped lists, which is what a cold prospect list is. Running your own SMTP server is possible, but you take on the IP reputation, the PTR record and your cloud host's port blocks.
We make Outreach2day, which sells mailbox SMTP for cold email. The quotes below come from each provider's own policy pages.
Two Kinds of SMTP
"SMTP" names a protocol, not a product. Two very different services use it:
Mailbox SMTP | Relay SMTP (email API) | |
|---|---|---|
What you get | A mailbox (name@yourdomain) with SMTP to send and IMAP to read | An endpoint that accepts mail from your app and delivers it |
Replies | Land in the mailbox; your sequencer reads them over IMAP | No inbox; replies go wherever your From or Reply-To points |
Warm-up | Possible: the mailbox exchanges mail and builds a history | Not applicable; the provider manages its IP pools |
Volume model | Many mailboxes, each sending a small number a day | One account sending large volumes |
Built for | One-to-one email from a person | Receipts, password resets, newsletters to opted-in lists |
Cold email allowed by the terms | Depends on the vendor; cold email vendors sell for it | No, per the policies quoted below |
Cold email is a sequence of one-to-one messages from a named person, where replies are the point. That is what a mailbox does. A relay sends from an application to people who asked for the mail.
What Relay SMTP Providers Say About Cold Email
Each policy below was read on the provider's own site. Where a policy does not mention purchased lists, we quote what it does say.
Provider | Policy | What it says |
|---|---|---|
SendGrid (Twilio) | Prohibits "Sending unsolicited or unwanted emails in bulk" and "Using purchased or rented email lists or email lists of recipients that have not affirmatively consented to receive emails from you". Also bans sending to addresses "obtained from the Internet or social media" without prior consent. | |
Amazon SES | The AUP bans using AWS "to distribute, publish, send, or facilitate the sending of unsolicited mass email". The FAQ says AWS may pause sending if mail "contains unsolicited or malicious content" or has high bounce or complaint rates. | |
Mailgun | "Acquiring or sending to a third-party mailing list is prohibited. Use of contact lists that are bought, rented or scraped from third-parties is prohibited by law in most countries, and is absolutely prohibited on Sinch Email servers." Non-transactional email needs "clear, explicit and provable consent". | |
Postmark | "All email lists contained and/or used with respect to the Service must be permission-based subscriptions. Use of a list that has been purchased or rented from a third party is prohibited." | |
Brevo | Lists "scraped on the internet, acquired or purchased from a third-party" are "strictly prohibited", and consent must be active and explicit. |
Sending to a cold prospect list through one of these services works against its terms, and the provider can suspend the account. Twilio's policy also names "snowshoeing", spreading mail across many domains or IPs to dilute reputation, as a prohibited practice.
Self-Hosted SMTP: What It Takes
Running Postfix, Mailcow or similar software on a VPS gives you a mail server you control. What the job involves:
An open outbound port 25. Many clouds block it. Google Cloud's guide to sending mail from a VM says "connections to destination TCP Port 25 are blocked when the destination is external to your VPC network". DigitalOcean's SMTP support page says ports 25, 465 and 587 are blocked on Droplets by default, and recommends against running your own mail server.
Forward and reverse DNS. Google's sender guidelines require the sending IP to have a PTR record that resolves to a hostname, and that hostname must resolve back to the same IP. Only the owner of the IP block can set the PTR, so your host has to support it.
SPF, DKIM and DMARC for every sending domain, pointing at your server. See SPF, DKIM and DMARC for cold email.
IP reputation from zero. A new IP has no sending history. You warm it up yourself, and if it gets listed, you deal with the delisting.
IMAP, TLS certificates, updates and monitoring. Your sequencer needs IMAP to read replies, and the server needs patching like any other.
The trade-off: self-hosting has no per-mailbox fee and no vendor rules, and in exchange you are the mail operations team. It fits a team that already runs mail servers. For everyone else, price the hours of setup and upkeep against a per-mailbox fee before you start.
What to Look For in an SMTP Provider for Cold Email
Mailboxes, not a relay. Each address should have its own IMAP login.
Your domains. Domains registered to you, or your own domains connected, so you can leave.
Warm-up. Included or available, and it should keep running while you send.
A stated daily limit. A vendor should tell you how many cold emails per mailbox a day it recommends. Ours is up to 25; see cold emails per mailbox per day.
Export. SMTP/IMAP credentials or a direct sync to your sequencer.
The full buyer's checklist, with vendors compared on each point, is in how to buy mailboxes for cold email. If you are deciding between SMTP mailboxes and Google or Microsoft seats, read Google Workspace alternatives for cold email.
How to Connect SMTP and IMAP to a Sequencer
Collect the credentials. For each mailbox you need the email address, the SMTP host, the IMAP host, the username (usually the full address) and the password.
Set the SMTP port. Use 465 for implicit TLS or 587 for STARTTLS. RFC 8314 describes both for message submission, and RFC 6409 reserves 587 for submission. Don't submit on port 25.
Set the IMAP port. Use 993 with implicit TLS, also per RFC 8314. The sequencer reads replies here to stop the sequence when a prospect answers.
Set the daily limit. Up to 25 cold emails per mailbox a day, not counting warm-up. Spread sending over the working day.
Keep warm-up running. Leave warm-up on for every mailbox while it sends; see why to keep warm-up running.
Send a test and check the headers. Send to a mailbox you control and confirm SPF, DKIM and DMARC pass.
For Instantly and Smartlead there is a shorter route than typing credentials: add mailboxes by API key. The same ports apply to Gmail's own server; our Gmail SMTP settings post covers that case.
Where Outreach2day Fits
Outreach2day sells mailbox SMTP: standard SMTP/IMAP mailboxes on your own domains, at $2.50 per mailbox a month from 12 mailboxes ($30). Each mailbox includes automatic SPF, DKIM and DMARC setup, warm-up, a sending engine with one inbox for replies, and per-mailbox analytics. New mailboxes are ready within 24 hours. You warm up for at least 14 days, start with low cold volume from day 14 and reach up to 25 cold emails a day from around day 21.
The logins work in any tool that accepts SMTP/IMAP, Instantly and Smartlead connect with an API key, and there is a REST API on every account. We don't sell Google Workspace, Microsoft 365 or a relay, and we don't guarantee inbox placement: it is measured per mailbox. See pricing.
FAQ
Can I use SendGrid for cold email?
Twilio's Email Policy, which covers SendGrid, prohibits unsolicited bulk email and lists of recipients who have not given affirmative consent. A cold prospect list does not meet that bar.
Can I use Amazon SES for cold email?
The AWS Acceptable Use Policy bans unsolicited mass email, and the SES FAQ says AWS may pause sending for mail with unsolicited content or high complaint rates.
Which SMTP port should I use for cold email?
Port 465 with implicit TLS or port 587 with STARTTLS for sending, and port 993 for IMAP. Port 25 is for server-to-server delivery and is blocked for outbound traffic on many clouds.
Is self-hosted SMTP good for cold email?
It can work if you control an IP with a proper PTR record, have outbound port 25 open and manage reputation yourself. The setup, warm-up and upkeep are all yours.
What is the difference between SMTP and IMAP?
SMTP sends mail; IMAP reads the mailbox. A cold email tool needs both: SMTP to send the sequence and IMAP to see replies and stop follow-ups.
Sources
Checked September 2026:
Twilio Email Policy: SendGrid ban on unsolicited bulk email, purchased lists, addresses from the internet, snowshoeing.
AWS Acceptable Use Policy: ban on unsolicited mass email.
Amazon SES FAQ: sending paused for unsolicited content or high bounce and complaint rates.
Mailgun Acceptable Use Policy: ban on bought, rented or scraped lists; consent requirement.
Postmark Terms of Service: permission-based lists only; purchased or rented lists prohibited.
Brevo Anti-spam Policy: scraped or purchased lists prohibited; active consent.
Google Cloud: sending email from an instance: outbound port 25 blocked.
DigitalOcean: why is SMTP blocked: ports 25, 465 and 587 blocked on Droplets.
Google email sender guidelines: PTR and forward DNS for sending IPs.
RFC 8314: implicit TLS on 465 for submission and 993 for IMAP; STARTTLS on 587.
RFC 6409: port 587 for message submission.
Get SMTP/IMAP mailboxes built for cold email, with warm-up and sending included.
Keep reading
Send 100,000 cold emails a month
How to send 100,000 cold emails a month while keeping quality, engagement and conversion rates high: domains, mailboxes, warm-up, leads, copy and scaling.
Step-by-step playbook · 19 min readDeliverability9 min read
Cold Email Deliverability 2026: What Changed, What to Do
Deliverability9 min read
Domains for Cold Email: How to Choose, Buy and Set Up
Deliverability8 min read
Email Warm-Up Schedule: Day-by-Day Plan for New Domains

