Okki-Go Setup Checklist: 7 Steps That Keep B2B Outbound From Blowing Up Your Sending Reputation
2026-09-22 · Julian Hartwell
-
When This Checklist Is For You
-
Step 1: Get SPF, DKIM, and DMARC Done Right
-
Step 2: Define What a Business Contact Actually Is — And Isn't
-
Step 3: Verify Every Email Address Through the API Before It Touches a Campaign
-
Step 4: Pull Company Context Through a Company Data API
-
Step 5: Turn On Decision Maker Search — But Don't Lean On It
-
Step 6: Keep a Human in the Loop — Even When You Don't Want To
-
Step 7: Measure Past Reply Rate
-
Common Mistakes and Gotchas
I run quality review on outbound for a B2B SaaS company — roughly 1,200 pre-send touches a month pass through my hands before anything leaves the building. In 2024 I rejected about 18% of first-draft sequences, mostly for sender authentication, domain reputation, or format issues that shouldn't have made it that far. This checklist is the one I wish every team had been handed on day one.
When This Checklist Is For You
This is for outbound teams of roughly 3 to 30 people wiring up okkigo (or migrating onto it) who need the setup to actually hold up under volume. Too small to have a dedicated RevOps person, too big to wing it per-rep.
I've ordered the seven steps sequentially because each one changes how you approach the next. Authentication defines which domains can send at all. Verification defines how much of your list is even real. Decision maker search depends on both of those being clean.
Realistic timeline: about a week end to end. Skip a step and it comes back at the exact moment you try to scale.
Step 1: Get SPF, DKIM, and DMARC Done Right
Not optional. Google and Yahoo's bulk sender rules went into effect in February 2024, and if you're pushing more than 5,000 messages a day into Gmail or Yahoo inboxes, SPF, DKIM, and DMARC all need to be compliant. Per RFC 7208 (SPF), RFC 6376 (DKIM), and RFC 7489 (DMARC) — the underlying specs are stable, but the inbox provider rules layered on top move fast. Verify current requirements at each provider's postmaster page before you finalize.
Three records, and they're not interchangeable:
- SPF — declares which IPs can send on behalf of your domain. One record per domain. More than 10 DNS lookups and it silently fails.
- DKIM — signs the message. k=rsa, p= needs to be at least 1024 bits. Use 2048 if you can swing it.
- DMARC — tells inbox providers what to do when SPF or DKIM fails. Start at p=none, look at what's breaking, then tighten.
Everything I'd read said get SPF right and you're mostly there. In practice, DKIM and DMARC are where things actually fall apart. SPF alone doesn't save you if your DKIM key is rotating or your DMARC policy is still sitting at p=none six months later.
Common failure I've seen more than once: the SPF record gets edited and picks up stale include: statements, so two lookups point at old providers, and the record just... stops working. You don't get an error. You just watch your open rate quietly tank.
Run every record through mxtoolbox or dmarcian before you send anything. Don't wait for the first bounce wave.
Step 2: Define What a Business Contact Actually Is — And Isn't
This is the step people skip and then wonder why their reply rate is 0.8%.
A business contact is someone who can move on your offer or influence the move. Not anyone with a company-domain email. Not anyone who happens to appear on your list.
Working test:
- They can say yes
- They can say no
- They have a reason to care about your offer, budget, or timeline
Role boxes — info@, hello@, support@ — are not business contacts no matter how good the deliverability looks. They're a deliverability trap.
One more: don't fill a business contact list with entry-level titles. Same reason. They can't say yes, so the conversation goes nowhere even if they reply.
Honest ratio: if you qualify 2,000 contacts out of a 5,000-row list and most of them are actually reachable decision-makers, you're doing fine. Most teams are closer to 20%.
Step 3: Verify Every Email Address Through the API Before It Touches a Campaign
This is the step I see skipped most often, and it's the one that does the most damage when skipped.
The API email verification documentation for most providers gives you results that aren't just valid/invalid. You get: valid, invalid, accept-all, unknown, role, disposable. Each one needs to be handled differently. If the docs are good, read them carefully. If they're vague, that's a signal.
How I sort them:
- Valid → send
- Invalid → never send. Not even retries.
- Accept-all → send, but throttle and watch
- Role → bust out separately, they belong in a different sequence
- Disposable → drop. They exist to defeat verification.
Takes about a day — or rather, it takes a day the first time and about an hour after that, once you've got the API wired into your flow.
The verification step isn't about hitting some magic percentage. It's about cutting obvious waste before you spend sender reputation on it. Saved $200 by skipping the verification step. Ended up spending far more on a domain warmup restart after the hard-bounce rate spiked in week two. Net loss.
Step 4: Pull Company Context Through a Company Data API
An API company data call gives you the stuff nobody puts on a LinkedIn headline: size, industry, tech stack, hiring signals, funding events. This is what makes the difference between an opening line that reads like a real note and one that reads like a mail merge.
The point isn't that you can get the data. It's what you do with it. A 40-person company needs a totally different opener than a 4,000-person one. Same product, same pain, but the framing has to shift or it's noise.
One caveat I want to be honest about: I don't have hard data on how much lift enrichment alone gives you on reply rate. What I can say anecdotally from our own runs is that sequences with company-context lines in the first paragraph outperform generic ones by a noticeable margin, though I couldn't tell you the exact number without pulling the last two quarters stat by stat.
Also: don't treat company data fields as a checkbox. Empty fields happen. Inference from public sources beats fabricated accuracy every time.
Step 5: Turn On Decision Maker Search — But Don't Lean On It
Okki-Go's decision maker search is the piece that saves the most manual research time. It's also the piece most likely to quietly poison a list if you treat it as ground truth.
Two things to keep in mind:
- It finds decision makers by title. Title is a proxy. A VP who's actually an IC, or a Director who's the real gatekeeper — the title doesn't always match the reality.
- The number one mistake is treating the output as a replacement for review instead of a starting point. Every contact it surfaces is a hypothesis until a human checks it against LinkedIn, the company site, and whatever they've actually published recently.
My protocol: search, export, then hand-review a 10-15% random sample weekly. Over a few months you'll learn exactly how much to trust it for your specific vertical. Usually: trust it, but not completely.
This is also where the quality_perception instinct kicks in. A wrong-name, wrong-title, wrong-company message to a real decision maker costs you the relationship before it starts. Fixing it later is much more expensive than vetting it now.
Step 6: Keep a Human in the Loop — Even When You Don't Want To
No amount of automation writes a message that sounds like a person wrote it for this specific recipient. That part stays manual.
Where the human needs to be:
- First-touch copy, at minimum reviewed by someone who's worked the segment
- Random sample of final verified output before it ships
- Send pacing — small batch, watch, then scale
Honestly, the labor cost is real. It's still cheaper than a reputation hit. At least, that's been my experience running this on our own outbound.
One thing that helped a lot: we built a two-week feedback loop with the SDR team. They flagged sequences that felt "off" before they went out. It's not formal QA, but catching three of those in week one paid for the whole review process.
Step 7: Measure Past Reply Rate
Reply rate is the number in the dashboard. It's also the last thing you should be looking at.
What to look at first:
- Deliverability rate into the inbox (not "sent")
- Bounce composition — hard, soft, and why
- Spam complaint rate — anything above 0.1% is a red flag
- Domain / reputation monitoring score
- Open-but-no-reply segments
This monitoring stack is something we only got up around month three. Before that we were staring at reply rate and couldn't see what was actually causing problems. Wish I'd built it on day one.
Common Mistakes and Gotchas
A short list of things I've seen go wrong, in no particular order:
- SPF-only setup. Without DKIM and DMARC, SPF does maybe half the work.
- Launching all sending domains at once. Ramp one or two, watch reputation move, then add the rest.
- Treating verification results as permanent. They expire. Re-run every campaign, not once per contact.
- Skipping the business contact definition. Sending to info@ and wondering why replies are cold is a budget-eating habit.
- Letting decision maker search do the thinking. It's a start, not a substitute.
- Assuming "no bounces" means "all good." Messages that land in spam don't bounce. Watch opens, replies, and reputation instead.
That's the list. If something changes on the authentication or verification side I'll come back and update — the fundamentals don't move much, but the edges do. As of early 2025, the order above is what I'd run for a fresh okkigo setup.