The 7-Step Outbound QA Checklist I Run Before Every B2B Campaign Goes Live

2026-09-23 · Kwesi Adom

Who this checklist is for

If you're about to launch a B2B outbound campaign in 2025 and your delivery list has wrong contacts, unverified emails, or missing email authentication, this is for you. Below are the seven steps I run through before any campaign goes live at okkigo. I've reviewed and rewritten this protocol probably 200+ times across different delivery systems (that's just 2024 numbers).

Total time if your data is clean: about 90 minutes. From scratch: a full afternoon.

One caveat — this is a QA checklist, not a mandatory sequential playbook. Steps 3 through 6 can run in parallel.

Step 1: Re-check SPF, DKIM, and DMARC. All three. Not two out of three.

Before you touch a single prospect list, get email authentication right.

These are three separate DNS records doing three separate jobs:

  • SPF (Sender Policy Framework) — lists servers allowed to send on your domain's behalf. Spec: RFC 7208.
  • DKIM (DomainKeys Identified Mail) — cryptographically signs each message so receivers can verify it. Spec: RFC 6376.
  • DMARC (Domain-based Message Authentication, Reporting & Conformance) — tells receiving services what to do when SPF and DKIM fail. Spec: RFC 7489.

Most teams set SPF, then stop. DKIM and DMARC? Those get the "we'll do it later" treatment.

What happens then: emails start landing in Promotions or Spam, and people start blaming "cold email is dead."

It isn't. The configuration is.

When I compared a single sending domain across Q2 and Q3 last year — same content, same list, the only change was a proper DMARC record with p=quarantine — deliverability roughly doubled. Not a small delta. Double.

My honest recommendation: set DMARC to p=none first. Get the reports flowing. Watch where your senders are actually failing. Then tighten the policy.

Step 2: Define what "business contact" actually means for your team

This step gets fuzzy faster than any other.

A business contact, broadly, is a professional contact associated with a company — not a generic info@ alias, not a personal Gmail from someone's old freelancing days. A real person with a real role at a real organization.

When should a B2B sales team use a business contact versus a warehouse address or a shared inbox? Almost always, whenever you're trying to reach the person who decides, and not the shared inbox nobody reads.

Here's the thing though: define your business contact by ICP, not by a title dictionary.

I've rejected first deliveries because someone's definition of "business contact" was just "anyone with a C-level title." If I'm running a list for a 40-person SaaS, I don't want CEO@ — that CEO is not the buyer for most tools at that size. The VP of Marketing probably is.

So write it down. Title ranges, department, seniority band. Then enforce it.

Step 3: Lock your ICP before you hand it to decision-maker search

Most people skip this. They jump straight to decision-maker search and end up with a huge, unfiltered name dump.

Write the filter first:

  • Revenue band or employee count
  • Industry or subindustry
  • Geography
  • Tech stack signal (optional)
  • Exclusions — the ones you always forget

Every list I've had to rework traces back to a missing exclusion rule. Every single one. Now I write exclusions before I write inclusions.

Step 4: Use decision-maker search, don't guess

An okki-go decision maker search takes your ICP and pulls matched people. You don't feed names into LinkedIn and hope the match is right.

I have mixed feelings about automation here. On one hand, manual research produces better quality per contact. On the other, if an SDR spends 40 minutes per contact researching, you're not going to hit scale. Ever.

The compromise: automate identity resolution, keep human judgment for angle selection. Let the tool find who. Let a person decide what to say.

Common mistake — treating "has a LinkedIn profile" as validation. That's an identity signal, not a relevance signal. A CFO with a profile is not automatically the right contact for a developer-tools pitch.

Step 5: Waterfall-enrich company data. One source is never enough.

API company data from a single vendor usually lands around 45-60% coverage for the fields most sales teams care about. Different vendors have different blind spots.

Waterfall enrichment chains multiple tools in order until a field is populated. Not magic. Coverage arithmetic.

Our own funnel went from roughly 58% fill rate to around 81% after moving to waterfall (internal Q2 2024 numbers — your mileage will vary by ICP).

One caution: waterfall pricing stacks. Each added layer raises your per-record cost. Prioritize fields by value — company revenue and employee count first, technographics later, if at all.

Step 6: Run API email verification before send. Every time.

Read this twice: no verifier gives you 100% accuracy. Anyone claiming 100% is selling you a guess dressed up as certainty.

What you get is real: fewer obvious traps, lower hard bounce rates, saved sender reputation.

The okki-go API email verification documentation walks through which endpoints exist, what status codes come back, and how batch limits shape your integration. Read it fully before coding — I've seen a dozen integrations hit throttling limits that were documented upfront but nobody read.

Bottom line: if I skip verification, hard bounces creep past 2% and deliverability starts to slide. That's the actual cost of skipping this step.

Step 7: Keep a human-in-the-loop gate. Always.

Human-in-the-loop outreach isn't about distrusting the automation. It's about adding the layer automation is bad at:

  • Choosing the right subset to actually contact
  • Tone-matching the sequence
  • Catching obvious mistakes (company was acquired, title is stale, person changed roles)

I run a final pass on every launch. Non-negotiable in my book.

Not ideal. Not scalable forever. But until the tools catch up, skipping this is how you end up on a blacklist.

Common mistakes I keep seeing before final QA

  • Buying "verified" lists and skipping verification anyway. Every. Single. Time.
  • Setting SPF but leaving DMARC stuck at p=none for a year. That's not "monitoring," that's neglect.
  • Defining business contacts by job title keyword instead of role within ICP.
  • Assuming one enrichment source covers everything. It covers 60%, max.
  • Ramping volume flat instead of warm-up. Warm-up takes weeks. Plan for it.

One more thing worth saying out loud: transparent vendors beat clever ones. I'd rather see a vendor list every fee upfront — even if the total is higher — than one offering a "huge discount" that quietly cuts scope. Same logic applies to your own outbound. Say what you do. Do what you said. Count the emails you actually sent.