Zheat Outbound

    Why new cold email domains get blacklisted: shared Cloudflare name servers and SURBL

    RJ

    RJ, Founder, ZheatUpdated

    Short answer

    In 2026 a lot of cold email setups lost half their replies without anything obvious breaking. The cause, as Lead Gen Jay describes in his breakdown of the wave, was a domain blacklist, SURBL, listing cold email domains in bulk. Even brand-new domains that had never sent an email were listed.

    The fingerprint was the name servers. For years the standard advice was to put every cold email domain on Cloudflare. Hundreds of similar-looking domains, bought together and sitting on the same shared name servers, are easy to spot as a cold email operation.

    The fix is to stop letting your domains be tied together: isolated name servers, no redirects to your main site, and checking every domain that appears in your emails, not only the sender.

    What the drop looked like

    It wasn't a mass suspension like Google's 2025 wave. It was quiet. Reply rates fell by half or more, for example from 3% to 1%, on setups that had been working for months. Warm-up, volume, copy and mailboxes hadn't changed.

    Most people looked at the usual suspects first: a Google or Microsoft update, the copy, the list, the volume. The giveaway came when teams replaced their worst domains. The new ones, with zero sending history and not even in warm-up yet, were already blacklisted. That rules out copy and sending reputation.

    Why a domain blacklist kills good emails

    Most blacklists track IP addresses, the servers that send mail. SURBL is different. It lists domains, wherever they appear in a message: the sending domain, a tracking domain, a link shortener, the landing page you link to.

    Once any domain in your email is listed, every email containing it is poisoned. It doesn't matter how clean the sender is or how long the warm-up ran. As the video puts it: "You can have a perfect sender and a dead message."

    The fingerprint: shared name servers

    Name servers tell the internet where a domain's DNS records live. Cloudflare gives each account a pair of name servers, and moving every cold email domain onto Cloudflare became the industry default. It was free, fast to automate, and good advice for years.

    The side effect: thousands of lookalike domains, registered at the same time, all pointing at the same few name servers. That is a pattern a blacklist can watch. In Lead Gen Jay's tests, domains added to a fresh Cloudflare account stayed clean, while domains added to an account that was already flagged were listed within about an hour.

    This isn't Cloudflare's fault. The whole industry did the same thing, which is exactly what made the pattern easy to find.

    Other patterns that tie domains together

    • Redirects to the main site. If every secondary domain redirects to the same website, anyone following the redirects can group them. In the video's tests this wasn't causing listings yet, but it's expected to.
    • Shared tool fingerprints. Every Google mailbox connected to the same sending tool goes through the same OAuth app. Nobody can fix that one alone, but it shows how many signals can link your domains.

    Which blacklists actually matter

    Hundreds of blacklists exist, and almost every domain shows up on some minor one. Most of them don't affect delivery. The ones that do are the lists mailbox providers and spam filters check: Spamhaus, Barracuda, and now SURBL for domains.

    Being on a minor list is not an emergency. Being on one of those is.

    How to check your setup

    1. Look up each sending domain on the SURBL lookup, then run a general blacklist check.
    2. Check every other domain in your emails too: tracking domain, link shortener, and your main website if you link to it.
    3. Look at your name servers. If hundreds of your domains share the same Cloudflare pair, that's the pattern being targeted.
    4. Ask your mailbox or infrastructure provider whether they use isolated name servers and avoid plain redirects.

    How to fix it

    • Isolated name servers. Give each group of domains its own name servers so they can't be linked. The video's team moved to AWS Route 53, which assigns separate name servers per hosted zone. If you only run a handful of domains, the registrar's default name servers are fine, as long as you're not one of thousands of cold email domains sharing them.
    • No redirects to your main site. Lead Gen Jay credits EmailGuard with pushing a domain masking proxy for a long time: the sending domain shows your real website through a proxy instead of redirecting, so there's no redirect chain to follow. It can be set up and tested in EmailGuard.
    • Fewer domains in each email. Every extra domain is another chance to be listed. Turning off open and click tracking removes the tracking domain, and skipping link shorteners removes another.
    • Already listed? Move the domain to isolated name servers first, then request removal from SURBL one domain at a time. Expect 30 days or more. For campaigns that can't wait, buying new domains on a clean setup is usually faster.

    According to the video, older domains that weren't already listed don't appear to be getting added. New domains on shared name servers are the ones at risk.

    Our take

    We already run open and click tracking off, no link shorteners and no attachments, so the only domain in most of our emails is the sender. Before launch and while campaigns run, we check placement, blacklists and DMARC with EmailGuard, and a domain that slips gets paused and replaced.

    What this wave changes is the checklist. Checking the sending domain isn't enough anymore: every domain in the message and the name servers behind it have to be checked too. A worthwhile caveat: Lead Gen Jay sells cold email infrastructure and pitches it in the video. The diagnosis matches what the wider cold email community reported, and the checks above cost nothing to run.

    FAQ

    Why are my brand-new cold email domains already blacklisted? Most likely because they sit on name servers shared with many other cold email domains. Domain blacklists like SURBL can list new domains on those name servers before they send anything.

    What is SURBL? A blacklist of domains that appear in spam messages. Spam filters check the domains inside an email, including links, against it. If any domain in your email is listed, the whole email is treated as suspect.

    Should I stop using Cloudflare for cold email domains? The problem is shared name servers, not Cloudflare itself. What matters is that your domains can't be grouped together. Isolated name servers, for example with AWS Route 53, solve that. A small number of domains on your registrar's default name servers is also fine.

    How long does it take to get off SURBL? Expect 30 days or more, and only after moving the domain to isolated name servers. If you need to send sooner, new domains on a clean setup are faster.

    Do I need to check more than my sending domain? Yes. Check every domain in your emails: tracking domain, link shortener, landing page and main website. One listed link is enough to sink a clean sender. We covered the rest of the inbox placement setup in why most cold email campaigns don't book meetings.

    Sources