SMTP for cold email: cold email SMTP service, server and provider options that actually deliver
The short answer
SMTP means two different things in cold email and only one of them works. If you mean a bulk SMTP relay or transactional email API such as SendGrid, Mailgun, Postmark, SMTP2GO, Mailjet or Resend, the answer is no, and not for deliverability folklore reasons: all six ban it in writing. SMTP2GO's terms require lists to be "100% opt-in" and name marketing leads and lists built via LinkedIn as not allowed. Mailgun calls bought, rented or scraped contact lists "absolutely prohibited". Postmark's terms prohibit a purchased or rented list outright. Relays are also one-way pipes, so replies, the only number a cold sequence is actually judged on, have nowhere useful to land. If you mean connecting your own real mailbox over SMTP, that does work, it is just the weaker option: OAuth into Google Workspace or Microsoft 365 gives proper reply threading and does not depend on an app password that breaks whenever security policy changes. AutoMail connects real mailboxes on your own secondary sending domains, warms each one, and rotates volume across the pool instead of pushing cold mail through a shared relay IP.
Almost everyone who searches for an SMTP service for cold email is asking one of two questions without realizing they are different questions. The first is which bulk relay to push campaign volume through. The second is how to connect the mailbox they already own to a sending tool. The first has an answer nobody likes and the second has an answer worth getting right.
Start with the relay question, because it is settled by the vendors rather than by opinion. Read the acceptable use policies instead of the marketing pages and the pattern is identical at every provider. Twilio SendGrid's email policy prohibits using purchased or rented lists, or lists of recipients who have not affirmatively consented, and lists sending unsolicited email in bulk as a prohibited action. Mailgun's policy states that acquiring or sending to a third-party mailing list is prohibited and that bought, rented or scraped contact lists are absolutely prohibited on its servers. Mailjet, which sits on the same Sinch infrastructure, carries the same language and separately forbids using the service to harvest or generate email addresses. Postmark's terms say a list purchased or rented from a third party is prohibited and warn that unsolicited email will generate abuse complaints against your account. SMTP2GO is the bluntest of the set: lists must be 100% opt-in, purchased lists and marketing leads including lists built via LinkedIn are not allowed, and it forbids unsolicited email of any kind. Resend prohibits unsolicited messages including cold outreach, purchased lists and scraped contact data by name.
So the compliance answer is unanimous, and the practical answer agrees with it. A shared relay pools IP reputation across thousands of tenants you cannot see, which means your deliverability is partly decided by whoever else is sending that hour. Relays are engineered for one-way traffic, so the reply, the single event a cold sequence exists to produce, comes back to a mailbox the relay knows nothing about, and reply detection, thread matching and sequence pausing all have to be bolted on somewhere else. Pricing assumes a shape outbound does not have: relays are priced for tens or hundreds of thousands of sends, while a healthy cold program runs 20 to 50 sends a day per mailbox. And Gmail and Microsoft increasingly weigh domain reputation and per-mailbox engagement history, which is exactly the signal a fresh relay stream does not carry.
Now the second question, which is the useful one. SMTP as a protocol is fine. Connecting your own Google Workspace or Microsoft 365 mailbox to a sending tool over SMTP and IMAP works, and plenty of tools still offer it. It is simply the weaker of the two ways in. SMTP plus IMAP needs an app password, which many US security teams have disabled outright, gives the tool a coarser view of the thread, and tends to break silently when a tenant policy changes. OAuth talks to the Gmail API or Microsoft Graph, survives policy changes, threads replies properly, and never asks anyone to mint a static credential. If a vendor only supports SMTP with an app password, that tells you something about how deep the integration goes.
The setup that actually holds up is unglamorous. Buy two or three secondary domains that resemble your brand and keep your primary domain out of outbound entirely. Put a small number of real mailboxes on each, on Google Workspace or Microsoft 365. Authenticate every sending domain with SPF, DKIM and an aligned DMARC record. Warm each mailbox for two to three weeks before it sends a single cold email, then spread daily volume across the whole pool so no individual inbox ever carries a load that looks automated.
AutoMail runs that pool as the product rather than as a checklist you maintain. It connects Google Workspace and Microsoft 365 mailboxes over OAuth, warms each one, rotates sends across the set, checks SPF, DKIM and DMARC alignment on every sending domain and refuses to send from one that fails. It writes a distinct email per prospect from researched detail instead of merging a template, runs the follow-up cadence, and stops the instant a human replies. Interested replies get classified and routed to your booking link. Every message carries a one-click unsubscribe and honors your suppression list, so the program stays CAN-SPAM ready as it scales.
It works hand in hand with email warmup tool, cold email tool and email outreach software, all included in one flat cold email software price.
Personalize · deliver · follow up · book
AutoMail researches and writes a 1:1 sequence. Sample data, nothing is sent.
Live, interactive · personalized · no card needed
Permission-based B2B outreach · 1-click unsubscribe in every send · deliverability protected
Flat monthly fee no per-seat gouging
Deliverability-first by design
Why it works
What your team gets with SMTP for cold email
Real mailboxes, not a shared relay
Sends leave from Google Workspace and Microsoft 365 mailboxes you own, so reputation is built on your own domains rather than pooled with every other tenant on a relay IP.
OAuth rather than an app password
Connecting over the Gmail API and Microsoft Graph threads replies correctly and keeps working when a security team disables basic authentication, which is where SMTP and IMAP setups quietly fail.
Volume by pool, not by pipe
Capacity grows by adding warmed mailboxes at 20 to 50 sends a day each, the shape cold email actually needs, instead of pushing one high-volume stream that mailbox providers read as bulk.
Read the policy, not the landing page
What each SMTP relay's own policy says about cold email
Every quote below is from the provider's own published terms or acceptable use policy, read first-party on 13 August 2026. None of these are our characterizations of their stance.
| Provider | What their own policy says, verbatim | What that means for cold outbound | How AutoMail differs |
|---|---|---|---|
| Twilio SendGrid | Prohibits "using purchased or rented email lists or email lists of recipients that have not affirmatively consented to receive emails from you", and lists "sending unsolicited or unwanted emails in bulk" as a prohibited action. | A prospect list you sourced or scraped is, by definition, a list of people who never affirmatively consented. There is no tier or plan that changes this. | Sends from mailboxes you own on domains you own, so no third party's consent policy governs whether your outbound is allowed to exist. |
| Mailgun (Sinch) | "Acquiring or sending to a third-party mailing list is prohibited." "Use of contact lists that are bought, rented or scraped from third-parties is prohibited by law in most countries, and is absolutely prohibited on Sinch Email servers." | The strongest wording of the group, and it covers scraped lists explicitly, which is how most B2B prospect lists are actually built. | Treats list sourcing as your decision and your compliance obligation under CAN-SPAM, not a hosting-provider permission question. |
| Mailjet (Sinch) | Same Sinch prohibition on bought, rented or scraped lists, plus a ban on using the service "to harvest or generate email addresses or otherwise determine the existence of unknown email addresses". | That second clause also rules out running email verification through the platform, which is a step most outbound programs depend on. | Verification and enrichment happen before the send, against your own data, with no platform restriction on checking an address. |
| Postmark | "Use of a list that has been purchased or rented from a third party is prohibited." "Emails sent unsolicited will receive abuse complaints that will be reflected on Your account." | Postmark's entire deliverability advantage comes from keeping prospecting traffic off its infrastructure, so enforcement is the product, not an afterthought. | Keeps transactional and outbound mail on genuinely separate domains and mailboxes, which is the separation Postmark is protecting. |
| SMTP2GO | "Lists must be 100% opt-in." "Examples of lists that are not allowed are purchased lists, email addresses scoured from the Internet, and marketing leads (including lists built via LinkedIn or obtained from a 3rd party)." "We forbid the use of the service to send unsolicited mass emails or unsolicited emails of any kind." | The only policy in the set that names LinkedIn-sourced lists specifically, which is where a large share of US B2B prospect data originates. | A LinkedIn-sourced or vendor-sourced list is a normal input. The compliance work is one-click unsubscribe, suppression and honest identification, which the platform enforces. |
| Resend | Prohibits "sending unsolicited messages of any kind, including cold outreach, purchased lists, or scraped contact data", and requires that all recipients "have explicitly opted in". | The only provider here that uses the words "cold outreach" in the policy text, so there is no room to argue interpretation. | Built for cold outreach as the primary use case rather than tolerated at the edge of a transactional product. |
Quotes read first-party on 13 August 2026 from each provider's published terms or acceptable use policy. Amazon SES is deliberately absent: its rules live in the AWS Acceptable Use Policy and SES documentation, both of which render client-side and could not be quoted verbatim, and we would rather leave a row out than paraphrase a policy second-hand. Providers change these documents, so check the current version before you rely on any of it.
What it handles
Personalized, delivered and booked on autopilot
AutoMail works your prospect list, researches each one and writes a personalized sequence, protects deliverability with inbox rotation and warm-up, auto follows up, detects replies and pauses, and books the meeting straight into your calendar and CRM.
- Connects Google Workspace and Microsoft 365 mailboxes over OAuth, no app passwords
- Warms every new mailbox before it sends a single cold email
- Rotates daily volume across the mailbox pool instead of one sending stream
- Verifies SPF, DKIM and DMARC alignment on each sending domain before it sends
- Detects replies in the mailbox itself and pauses the sequence immediately
- Adds one-click unsubscribe and honors suppression lists on every send
Illustration of the sequence view. Placeholder data, not a customer account.
Why AutoMail
One cold email engine that runs the whole outbound job
Not a mail merge, not a template doc, and not a spray-and-pray blast. Personalize, deliver, follow up and book meetings in one place, with deliverability and compliance built in.
Personalizes every email
AutoMail researches your whole list and writes a hyper-personalized sequence for each prospect, so every email reads like you wrote it by hand and no good prospect gets a generic blast.
Lands in the inbox
Inbox rotation, automatic warm-up, real sender identity and a one-click unsubscribe in every email keep your outreach permission-based and inside CAN-SPAM and GDPR, automatically.
Books the meeting
Reply detection pauses the sequence the moment a prospect responds, and interested prospects get booked straight into your calendar and synced to your CRM, so your reps walk into meetings.
Good questions
Questions about SMTP for cold email
Explore more
More ways sales teams book meetings with AutoMail
Email warmup tool
Warm up your mailboxes so cold email lands in the primary inbox.
Learn moreCold email tool
Write, send and follow up on cold email that actually lands and books meetings.
Learn moreEmail outreach software
Outreach software that personalizes, sends, follows up and books from one place.
Learn morePut your cold email on autopilot.
Upload your prospects and AutoMail writes a personalized sequence for every one, protects deliverability with inbox rotation and warm-up, auto follows up, pauses on reply and books meetings into your calendar. Flat monthly fee, not per-seat.
1-click unsubscribe in every email · suppression honored · CAN-SPAM and GDPR