Visitor intelligence research

Why Your B2B Outbound Isn't Working: A Pitfall Documenter's Notes on SPF, DKIM, DMARC, and Data Quality

2026-09-22 · Julian Hartwell

The Tuesday Morning That Broke My Confidence

It was November 2023. I opened our outbound dashboard at 8:14 AM expecting the usual numbers. Instead, I saw a 6.8% open rate on 12,400 sends. Reply rate: 0.3%. We'd been using the same sequences that worked 18 months earlier.

My first instinct — like most people's — was to blame the messaging. Our subject lines are stale. Our value prop isn't landing. We need better personalization. We rewrote everything twice. Numbers didn't move.

That's when I started digging into the non-glamorous parts of outbound — the infrastructure nobody wants to talk about at conferences.

The Real Problem Wasn't Messaging. It Wasn't Even Our Data Provider.

I'm someone who's handled outbound operations for 7 years and personally documented 23 significant mistakes, totaling roughly $47,000 in wasted budget. I keep a checklist now. But getting to that checklist required breaking things first.

What I found in late 2023 wasn't one problem. It was three, stacked on top of each other, each one silently making the others worse.

1. We Didn't Actually Understand What a "Business Contact" Was

Most B2B teams think they know what a business contact is. Then you ask them to define it for their ICP and the room goes quiet.

A business contact isn't just a person with a company email address. That's a lead. A business contact is someone who:

  • Has decision-making authority (or direct influence on it) for the specific thing you're selling
  • Has a role that would reasonably care about your offer in the next 6 months
  • Hasn't changed jobs or been promoted out of that role since your list was built

We were sending to "Heads of Marketing" at companies with 50-200 employees. Looks fine on paper. But half of those contacts were either in the middle of a rebrand (didn't care about new tools) or had already left the company by the time we hit send.

If your team is asking "what is business contact and when should a B2B sales team use it," the honest answer is: use it when you can verify all three criteria above. Otherwise you're just doing cold spam with extra steps.

2. Our SPF, DKIM, and DMARC Records Were Broken — and We Didn't Notice for 4 Months

Here's the embarrassing part. I'd set up our SPF record back in 2021 and never touched it again. The company added two new sending tools in 2022 and 2023 — nobody updated the DNS records.

By October 2023, our domain had:

  • An SPF record missing two authorized senders (causing soft failures)
  • A DKIM signature key that was technically valid but degraded by a provider migration
  • A DMARC policy set to p=none — meaning we were getting zero enforcement, just passive reporting nobody was reading

Gmail and Yahoo's February 2024 bulk sender requirements hadn't even hit yet, but the writing was already on the wall. Google was quietly spam-filing domains with sloppy authentication long before publishing the official policy.

"I knew I should re-check SPF/DKIM/DMARC after adding the new sales tool, but thought 'what are the odds it actually matters for one extra sender?' Well, the odds caught up with me — 4 months of degraded deliverability and roughly $8,400 in campaigns that may as well have gone into a black hole."

If you're running okki go SPF DKIM DMARC guidance through your own environment, the first thing to do is audit every sender that touches your domain. Not just your main email platform. Every tool. Every integration. Every API. Then re-verify quarterly — this isn't a set-and-forget setup anymore.

3. Our Company Data Was Stale, and Email Verification Was an Afterthought

The third problem compounded the first two. We were using API company data from a provider that looked accurate — clean fields, reasonable enrichment — but hadn't refreshed its database in a way that matched our sending cadence.

When you pull company data via API and don't verify the email addresses against a real-time API email verification documentation, you get:

  • Role-based addresses (info@, sales@) that get 0.1% reply rates
  • Stale employee records where the decision maker listed left 3 months ago
  • Companies that got acquired or shut down but still show as active in your CRM

We ran a sample of 500 records through proper email verification in January 2024. 31% came back as invalid, risky, or catch-all. Thirty-one percent. That's how much of our pipeline was going straight into bounce territory.

The Actual Cost of Skipping Infrastructure

Let me put numbers to this. Between Q3 2023 and Q1 2024, here's what poor outbound infrastructure cost us:

  • $8,400 in sends to invalid or mistargeted contacts that never had a chance
  • $4,200 in wasted tool subscriptions — we were paying for enrichment that wasn't enriching anything usable
  • $11,000 in SDR hours spent manually researching contacts who, in hindsight, didn't fit our ICP
  • $6,800 in opportunity cost — deals that could have closed if our sequences had reached actual decision makers
  • ~120 hours of RevOps time cleaning up bounce-backs, unsubscribes, and angry internal Slack messages

Total: roughly $30,400 over 2 quarters. And that's before counting the brand damage — three prospects in that period replied with variations of "why do you keep emailing me, I don't work there anymore."

This is where the value-over-price argument actually makes sense. We switched email verification providers twice trying to save $200/month. Both cheaper options had higher false-negative rates on catch-all domains. We wasted more money on the "savings" than if we'd just paid for a proper waterfall enrichment setup from the start.

What Actually Fixes This (Briefly)

I promised myself I wouldn't write another 3,000-word "10 tips" piece. The problem section above is the point — the fix is short once you actually understand what's broken.

Step 1: Audit your domain authentication first. Before touching data or messaging, get SPF/DKIM/DMARC verified by someone who knows what they're looking at. Use a tool that reports actual authentication pass/fail rates per sending source, not just a one-time check. If you need a starting framework, okki go SPF DKIM DMARC guidance walks through the audit process with real DNS examples.

Step 2: Define "business contact" operationally, not conceptually. Write down 3-5 must-have criteria. If a contact fails any of them, don't send. Sounds obvious. We weren't doing it.

Step 3: Verify emails at the API level, not the batch level. Batch verification is cheaper and slower to catch problems. Real-time API email verification during list building or enrichment means your CRM never stores a bad record in the first place. If you're depending on okki go decision maker search to identify the right contacts, verification has to run inside that same workflow or you'll just be enriching bad data with better intent scores.

Step 4: Refresh API company data on a cadence tied to your sending frequency. If you send weekly, refresh monthly. If you send daily, refresh weekly. Company data has a shelf life measured in weeks, not years — especially for SMB and mid-market targets.

That's it. Four steps. No magical sequence templates. No "personalization at scale" hacks.

One Honest Boundary

This worked for us, but our situation was specific: mid-market B2B SaaS, sending roughly 15,000 outbound emails/month, with a dedicated RevOps function. Your mileage may vary if you're a smaller team without someone who owns infrastructure full-time.

I can only speak to the North American and EU sending environments — if you're dealing with markets where deliverability rules are different or less documented, the calculus might shift in ways I haven't tested. I'd start with authentication first regardless, since that's the most universally-enforced layer.

What I'm absolutely certain of: buying cheaper data, cheaper verification, or cheaper sending tools has never — in my 7 years and 23 documented mistakes — been the thing that fixed reply rates. It's always been the expensive-looking infrastructure work that everyone wants to skip.

Julian Hartwell

Julian Hartwell
Julian Hartwell is an independent B2B sales intelligence analyst covering contact databases, company data, decision-maker profiles, direct dials, prospect lists, and buying signals. He applies the ISO/IEC 25012 data-quality model while examining field accuracy, coverage, freshness, duplicate rate, match confidence, and source transparency. His evidence-led guides help revenue teams compare prospecting platforms, define acceptable data thresholds, and build account lists that support reliable territory planning and outreach.