Bounce rate is the most underrated number in cold email, and the reason is a bit of psychology: a bounce feels like a lost lead, so people file it under disappointment rather than danger.
It is danger. A bounce is not a lead you failed to reach, it is a public statement to every major provider about how carefully you collect data.
The numbers
| Bounce rate | What it means | What to do |
|---|---|---|
| Under 1% | Excellent. Verified, recent list | Carry on |
| 1 to 2% | Normal and healthy | Carry on, keep verifying |
| 2 to 3% | Warning zone | Check your source and verification |
| 3 to 5% | Providers are already reacting | Stop, clean the list, then resume slowly |
| Over 5% | Serious reputation damage in progress | Stop everything and rebuild the list |
These thresholds surprise people. Five percent sounds small. In deliverability terms it is a flashing sign saying that you did not check who you were writing to.
Hard versus soft
Hard bounces are permanent failures. The mailbox does not exist, the domain does not accept mail, the address is malformed. These are the ones that cost you, because there is only one plausible explanation for a hard bounce: you sent to an address you had not confirmed existed.
Soft bounces are temporary. Mailbox full, server unavailable, message too large, greylisting. These are mostly harmless, and any decent sending system retries them automatically. A soft bounce that persists across several attempts should be treated as a hard bounce.
There is also a middle category worth understanding. Some domains are configured to accept mail for any address at that domain, so verification cannot confirm whether a specific mailbox exists. These are usually reported as "risky", "accept-all" or "catch-all". They are a judgement call: acceptable in a small, well-targeted campaign where the address came from a credible source, unwise in bulk.
Where bounces actually come from
Purchased and rented lists. The largest single cause. These decay from the moment they are compiled and get resold repeatedly, so by the time you buy one it has already burned several senders.
Guessed patterns sent without verification. Generating five variations of a name and sending to all of them is a technique with a built-in 80% bounce rate. It is also, unfortunately, common.
Old data. Business email decays at roughly a quarter of records a year through job changes, closures and rebrands. A list from eighteen months ago is a third wrong before you start.
Typos at capture. Manual entry, form submissions, transcription from a phone call. Small in volume, easy to catch with verification.
Deliberate traps. Some addresses exist purely to catch senders who did not collect data properly. Hitting one is disproportionately damaging, and they are concentrated in exactly the kind of old, purchased list described above.
The prevention, which is almost trivially easy
Verification checks whether a domain accepts mail and whether a specific mailbox exists, without delivering anything. It takes seconds per address in bulk and costs a fraction of a cent.
The workflow:
- Verify every address before its first send. Not just the suspicious ones. All of them.
- Remove anything flagged invalid. Do not send anyway to double-check. That is what the check was.
- Decide a policy on risky and accept-all results and apply it consistently.
- Re-verify anything older than six months before reusing it.
- Remove hard bounces permanently the moment they arrive, and never re-import them later.
That is the entire discipline. The reason it fails in practice is not that people disagree with it, it is that it is a manual step somebody has to remember on a Friday afternoon. Which is why validating at the point of sending and simply skipping anything invalid matters more than it sounds: it converts a discipline problem into a non-problem.
If a campaign starts bouncing right now
Stop it. Immediately, not at the end of the batch.
This is the counterintuitive part. The instinct is to let the send finish, because the damage is already done. It is not: every additional bounce adds to the signal, and a campaign paused at 300 sends does considerably less harm than the same campaign at 3,000.
Then:
- Pause all sending from that mailbox. Keep warm-up running; it is doing repair work.
- Export the list and verify all of it, not only the portion that already bounced.
- Work out where that data came from, and stop using that source.
- Wait a week before sending anything cold from that mailbox.
- Resume at roughly a third of your previous volume and climb back over two to three weeks.
Recovery takes weeks. Verification would have taken minutes. This asymmetry is the whole argument.
The one habit that matters most
If you take one thing away, take this: treat your sending domain as an asset with a balance, not a resource with a quota.
Every verified send to a relevant recipient who engages adds to the balance. Every bounce, complaint and ignored message subtracts. Volume is not the constraint; the balance is. And a bounce is the single largest withdrawal available, made in exchange for absolutely nothing, since the message was never delivered to anybody.
Nobody has ever regretted verifying a list. A great many people have regretted not doing it, usually about three weeks later, when they cannot work out why nothing lands any more.
