An agency that runs cold email for many clients needs four things the single-company setup does not: strict separation between clients (domains, mailboxes, lists and suppression), a budget for each client, reports the client can verify, and clear rules about who owns what and who answers to whom. Everything else is the same work as for one company, repeated per client. The agency’s real risk is one client’s mistake spreading to the others.
This article describes the operating model, the separation that matters and why, what to put in a client report, how branding works, and the pitfalls that show up once you have more than a few clients. The product section at the end describes how Dooxout supports this. Pricing numbers are not given, because they are yours to set.
Why agencies are different
A company sending its own outreach owns its reputation. An agency holds the reputation of many companies at once, and their offers, lists and standards differ. Four things follow:
- Shared fate. If clients share domains, mailboxes or sending IPs, the worst client sets the delivery of the rest.
- Mixed accountability. The client owns the offer, the agency runs the operation. When a recipient complains, both are in the frame.
- Reporting is the product. The client does not see your mailboxes. They see numbers, so the numbers have to be right and the same each month.
- Margins depend on setup effort. Each client needs domains, DNS, mailboxes, a brief and a list. If every client is onboarded by hand, the margin disappears.
Separate everything that carries reputation
Mailbox providers evaluate senders by domain. Google’s Postmaster Tools, for instance, describes its domain reputation dashboard as showing only messages sent from the exact domain used for DKIM and SPF authentication, and Google counts bulk volume across all subdomains of one primary domain. Practical rules:
| Layer | Per client or shared | Why |
|---|---|---|
| Sending domains | Per client | A domain’s complaints and bounces are its own record |
| Mailboxes | Per client | A mailbox that gets flagged should not be carrying another client’s mail |
| Tracking domain | Per client or branded | Links in one client’s mail should not borrow another’s reputation |
| Suppression list | Per client by default | Opt-outs belong to the client’s own mail |
| Leads and campaigns | Per client | Prevents mixing audiences and offers |
| Budget and caps | Per client | One client’s spending or volume cannot consume another’s |
Two decisions are yours to make on suppression:
- Default scope. A person who unsubscribes from client A’s mail has not asked client B to stop. The FTC’s guide describes the opt-out as a request about “marketing email from you”, the business whose message it is. Per-client suppression is therefore the normal rule.
- A shared block list. You may still keep an agency-wide list for addresses that complained about anyone, or for domains that should never be contacted. That is a policy choice, and it protects you.
Who owns the domains
Decide before the first client signs. Options:
| Model | Pros | Cons |
|---|---|---|
| Agency owns the domains | Fast setup, consistent quality, agency controls DNS | Client may want to keep them at exit, and the agency carries the risk |
| Client owns look-alike domains, agency has DNS access | Clean exit, client owns the asset | Slower onboarding, and the agency depends on the client’s cooperation |
| Client’s main domain | No setup | Not recommended: cold mail risk lands on the client’s real domain. See cold email infrastructure |
Whatever you choose, write down what happens to domains, mailboxes and lead data at the end of the contract.
Legal and compliance duties
CAN-SPAM applies to commercial email, the FTC says it makes no exception for business-to-business mail, and it requires accurate header information, a non-deceptive subject, a valid physical postal address, a clear opt-out that works for at least 30 days, and honoring opt-outs within 10 business days. The guide also says that hiring another company to handle email marketing does not transfer the legal responsibility. For an agency this means:
- Write rules into the contract: who supplies the list, who approves copy, which address appears in the footer, who handles opt-outs and complaints.
- Whose address and brand? The messages should identify the business that initiated them. The footer needs a valid postal address for that business.
- Keep records: the approval of each campaign, the source of the list, and the date of each suppression.
- Honor opt-outs fast. Google asks for unsubscribes within 48 hours and Yahoo within 2 days, both shorter than the legal limit. See Gmail and Yahoo bulk sender requirements.
Rules outside the US, such as GDPR, are outside the scope of this article, so ask a lawyer if you send to Europe. This is not legal advice.
Budgets that stop a client, not the agency
An agency pays for many clients’ domains, mailboxes and leads, and an agency without budgets discovers overspending after the invoice. Use three levels:
- An overall cap for the agency account.
- A budget per client, for paid actions such as buying domains and mailboxes, lead searches and agent usage.
- Approval rules per client for large or irreversible actions.
A reached budget should block the next paid action, not the sending of what is already paid for. Otherwise a budget turns into an outage in the middle of a campaign.
If you bill clients, the margin formula is simple, and the cost side comes from the cost model:
Client cost per month = mailboxes*p_m + domains*p_d/12 + leads*p_l + software share
Client price per month = your fee (retainer, per mailbox, or per positive reply)
Margin = price - cost
Retainers fit when volume is stable. Pricing per positive reply moves the performance risk to you, and it needs the metric to be defined in the contract: what counts as positive, over what window, and who decides.
Reporting that clients trust
Send the same report, in the same format, on a fixed day. Content:
| Section | Numbers |
|---|---|
| Volume | Emails sent, delivered, leads contacted |
| Health | Bounce rate, unsubscribe rate, complaint rate |
| Response | Replies, positive replies, positive reply rate per delivered message |
| Result | Meetings booked, and, if known, opportunities |
| Spend | What was spent on domains, mailboxes and leads |
| Notes | Tests run and their outcome, what changes next |
Rules for a report that survives a skeptical client:
- Count, do not estimate. If a number is an estimate, label it as one.
- Skip opens. They are inflated by automatic loading of images. A client who sees 55% opens will expect results the replies will not deliver.
- Define positive reply in writing, and apply it the same way every month.
- Show tests honestly. Use the approach in A/B testing cold email, including “no difference” results.
Branding
White label means the client sees your name. In practice that covers the console, the email footer, the unsubscribe page, PDF reports and a custom domain for the console and tracking links. Check the edges:
- Mailbox sign-in screens. If a client connects a Google or Microsoft mailbox, the consent screen shows the name of the platform’s application, not the agency’s. Tell clients in advance.
- Sending domains. A look-alike domain is visible to recipients in any case, so choose names that represent the client honestly.
- Support. Decide who answers the client’s questions, and where those arrive.
Pitfalls once you have more than a few clients
- Onboarding without DNS access. A client’s IT team takes weeks. Ask for access or a person on day one.
- Reusing a “good” mailbox across clients. It moves the risk and mixes the data.
- No one owns the list. A client who supplies a list of unknown origin gives you the complaints.
- No pause rule. Agree in advance what bounce or complaint level pauses a client’s sending, and who can restart it.
- Manual reporting. A report that takes two hours per client does not scale past ten clients.
- Unclear exit. When a client leaves, they want their domains and replies. Plan it.
- Promising results. No one controls inbox placement, so contracts should promise activity and process, not delivery rates.
An onboarding checklist for each client
- Signed agreement with list, copy, address and opt-out rules.
- A separate workspace with its own budget and caps.
- Sending domains registered, with SPF, DKIM and DMARC in place. See SPF, DKIM and DMARC.
- Mailboxes created, and a preflight check passed. See the deliverability audit checklist.
- Brief, target profile and list source recorded.
- First campaign approved by a named person at the client.
- Report format and date agreed.
How Dooxout handles this
An agency account in Dooxout holds one workspace per client. Each has its own sending domains, mailboxes, leads, campaigns, suppression list, budget and policy, so a conservative setup for one client does not touch another. The agency pays: domains, mailboxes, leads and agent tokens used in a client workspace are counted per workspace and charged to the agency, so clients need no payment method on the platform. You set an overall cap and a budget per client, and a reached budget blocks that client’s next paid action, not the sending of what is already paid.
Roles cover operators who run campaigns, viewers who read reports and approvers who sign off. The brand profile holds name, logo, colors, a custom domain and a tracking domain, and applies to the console, emails, the unsubscribe page and PDF reports. Reports count sent, delivered, replied and spent, and can be shared as read-only white-label PDFs. The Google or Microsoft sign-in screen does not carry the agency brand.
Unsubscribed and complaining addresses are suppressed in that workspace on every channel, and no one can switch that off. Your own agent can connect over MCP with a token that has its own scopes and budget, under the same limits. The platform warns and recommends, and the decision stays with the agency and the client. See agencies, white-label cold email platform, pricing and guardrails and security.
Frequently asked questions
Should each client have its own sending domain?
Yes, as a default. Mailbox providers judge a sending domain on its own record, and Google counts messages by primary domain. If two clients share a domain, one client's complaints affect the other's delivery. Separate domains, mailboxes and suppression lists per client keep a problem small. Decide in the contract who owns the domains.
Who is legally responsible for a client's cold email?
The FTC's CAN-SPAM guide says you cannot contract away your legal responsibility to comply with the law when another company handles your email marketing. Treat the agency and the client as both accountable, and write the rules for lists, offers, addresses and opt-outs into the agreement. This is not legal advice.
What should a client report contain?
Counts the client can verify: emails sent and delivered, bounces, unsubscribes and complaints, replies, positive replies and meetings booked, and spend. Leave open rate out, because automatic image loading makes it unreliable. See why open rates lie.
What does white label mean in cold email software?
It means the client sees your brand instead of the platform's: your name, logo, colors and domain on the console, the emails' footer and unsubscribe page, and the reports. Some third-party screens may still show the platform, so check where a client's mailbox sign-in or consent screen appears. See the agencies page.
Sources
The external facts in this article were checked against these pages on . Provider limits and rules change, so check the current page before you rely on a number.