One subdomain per stream, on one condition nobody quotes

by Francis Rozange | Sep 8, 2026 | Email Marketing

The recommendation is everywhere: separate your sending streams by subdomain. One for invoices, one for newsletters, one for prospecting.

It has a primary source, which is rare enough to be worth noting. It also has a condition, almost always left out, which makes it harmful for most of the companies that apply it.

What M3AAWG recommends

The document is titled Sending Domains Best Common Practices, dated October 2019, and signed by the body that brings together mailbox providers. Its recommendation is unambiguous:

“It is strongly recommended that senders assign a separate subdomain of the main domain name for each distinct sending purpose.”

The reason is given just before:

“Receivers request (and may require) that different types of email traffic be separated when possible, distinguishing between, for example, bulk marketing, one-to-one prospection, transactions (welcome, order confirmation, etc.), monthly statements, and the like. […] These separations all require distinct subdomains, and in certain cases distinct IP addresses, too.”

The reasoning is sound. Reputation is built on behaviour. An invoice and a promotion do not behave alike: the first is opened, never reported, never unsubscribed from; the second carries a non-zero complaint rate by nature. Mixing them makes the invoice carry the promotion’s liabilities.

The document even gives the names: offers.mybrand.com for marketing, info.mybrand.com for transactional. With this precision: “The subdomain name should be relevant to the type of email traffic sent to avoid confusion for both the recipient and the filtering system (which may include people-based review, so ‘words matter’).”

The condition nobody quotes

It sits at the end of the same section, and it changes everything:

“Segmentation decisions should, however, be made in such a way that each segment can create and grow its own reputation, which requires sufficient and relatively consistent traffic volume. Lapses in sending or major fluctuations in traffic volume can impact both forming and sustaining sending reputation.”

Each segment must be able to build its own reputation. Which requires sufficient and regular volume. On each segment.

A company sending three thousand messages a month and splitting them across three subdomains has not created three reputations. It has created three signals too weak to interpret, where it previously had one, weak but legible.

And M3AAWG says so explicitly, in the sentence guides copy least:

“Especially for bulk sending, using distinct subdomains is industry best practice. However, for smaller volumes of email, it is acceptable to use different local parts of the sender address.”

For small volumes, changing the left-hand side of the address is enough. invoices@mybrand.com and letter@mybrand.com: one domain, one reputation, one authentication setup to maintain.

That sentence alone saves thousands of companies weeks of work.

The real cost of separation

It is not in creating the subdomain, which takes five minutes. It is in everything that follows.

Each subdomain needs its own SPF record, with its own includes, and its own budget of ten DNS lookups. Each subdomain needs its own DKIM key. M3AAWG recommends as much: “It is best practice for each sending subdomain to send using a different selector.”

Each subdomain starts from zero reputation, including under an old, well-established parent domain. M3AAWG is categorical: “When sending from a new subdomain, to be safe, domain warming is recommended even if the organizational level domain already has an established reputation.” And warm-up has no published schedule.

Each subdomain must be covered by your DMARC policy, which rules out the convenience of sp=none. If your subdomain policy is permissive, you have multiplied the doors opened in your name.

Three subdomains means three times those four projects, maintained over time, through key rotations and provider changes.

A freedom most people do not know about

The document settles, in passing, a recurring commercial objection, the one from the marketing team refusing to see offers.mybrand.com appear in the customer’s inbox:

“It should be noted that sending from different subdomains does not mean that the visible From: must also use the subdomain, so long as the organizational domains in each match.”

You can therefore sign and send technically from a subdomain while displaying a sender address on the main domain, provided the organizational domain is the same on both sides. That is the relaxed alignment DMARC allows by default.

The document adds a sensible caveat: “Senders should, however, have access to the inbox specified in the visible From:.” The displayed address must receive replies, and someone must read them.

What the operators say themselves

Google nowhere recommends separating by subdomain. It recommends separating by IP address, which is not the same decision:

“Ideally, send all messages from the same IP address. If you must send from multiple IP addresses, use a different IP address for each message type. For example, use one IP address for sending account notifications and a different IP address for sending promotional messages.”

Note the order of priorities: ideally, one single IP. Separation only comes second, if you must.

And Google definitively closes a door many hope to open with subdomains: sends from a domain and its subdomains are added together for the bulk sender threshold. Splitting your sending does not take you under five thousand.

What to do tomorrow morning

Count your monthly sends by message type. Not your list, your actual sends.

If one of your streams does not reach a few thousand messages a month, regularly, do not give it a subdomain. Give it a distinct sender address on the main domain, and keep one reputation to watch. It is M3AAWG that authorises this, not laziness.

If your streams are large and genuinely different in nature, separate them, but separate them fully: one subdomain, one DKIM selector, one SPF record, an inherited DMARC policy, and a proper warm-up. A half-done separation is worse than none, because it divides the volume without isolating the reputation.

And if someone proposes separating your streams to “protect the main domain” from your prospecting, listen closely to the word protect. It often means sacrificing a disposable domain, which is not a deliverability architecture but a practice the same body files under abuse.

Sources


LaFactory works email on the evidence: headers, DNS records, rejection logs. No open rate promises, ever. Get in touch for a deliverability audit.

Cart