Validity launched Heatwave, a domain blocklist aimed at synthetic warming and cold outreach, on September 3, 2026. A week later we ran a sample of 1,055 domains through it, pulled from our CRM on two criteria: the company had contacted us about a deliverability or reputation problem, and the domain was sending mail at the time. Eleven were listed. Another 127 were sitting under the threshold. The pattern in who ended up where is the reason for this post.
What the Heatwave blocklist is: synthetic reputation warming and cold outreach
Heatwave lists domains that show the signature of artificial warming: a network of fake mailboxes sending each other short messages, opening them, clicking and replying, so that Gmail and Microsoft record engagement before a real recipient has heard from the domain. Every warmup service sells some version of that loop, usually with lookalike domains registered on your behalf so the warming doesn't touch your primary domain. Heatwave finds the lookalikes and the primary domain behind them. It is mirrored into Validity's existing DNS reputation zones, which is how Comcast, Proofpoint, Spamhaus and SURBL already have it.
You can check a domain at lookup.validity.tools. It returns not listed, listed, or "candidate", meaning Heatwave has observed signals that haven't met the listing threshold. It also shows how many listed lookalikes are tied to the domain you entered.
The numbers
Of the 1,055 domains in the sample, 917 (86.9%) came back clean. 127 (12.0%) were candidates. 11 (1.0%) were listed.
Six of the 11 were classified as synthetic warming only. Five were warming followed by active cold outreach. Listing scores ran from 27 to 41 out of 100; Validity describes the score as a relative severity band against other listed domains, recomputed hourly, not a fixed measure of any one domain.
77 domains (7.3%) had listed lookalikes attached, 1,521 lookalike domains in total, median 11 per domain, one with over 150.
The earliest listing in the results is dated July 20, six weeks before Validity announced the list. Anyone listed over the summer had nothing to check.
Who was listed
None of the 11 listed domains belonged to a company that was working with us when the listing happened. Every listing predates any engagement.
About half had contacted us with a deliverability problem, priced the work, and went another way: a warmup subscription, an outreach tool, or a cheaper vendor. Several of them came back later with a SURBL listing they couldn't explain, and Heatwave now shows what happened in between. The rest had an intro call or asked about pricing and never went further. All five of the "warming plus cold outreach" listings are in these two groups.
The candidates we recognized follow the same line: companies that had the conversation about the work and chose not to proceed, now sitting under the threshold.
Most of these are ordinary businesses that had a real problem and took the option that promised to fix it in a few weeks.
Two current clients under the threshold
One client's domain is a candidate because of a warming service they signed up for before they contacted us. It didn't help, which is why they called. The service has been disconnected for months. Heatwave still holds the record: the lookup returns "signals observed; listing threshold not met." The DNS answer for the same domain is NXDOMAIN, so the holding state is visible only in the web tool, not to anyone pulling the zone. Stopping the activity does not remove it from the dataset.

A second client is a candidate with no lookalikes attached, and we're tracing the source. The first thing we check on any candidate result now is whether someone on the sales team has an outreach tool running.
Impersonation puts the wrong domain on the list
The domain with over 150 listed lookalikes is a consumer platform with hundreds of millions of users. It isn't warming anything and it isn't listed. Look at what the lookup attaches to it, though: most of the 154 domains aren't imitations of the brand at all. They're names that happen to contain the same string, "AI cloud" and "API cloud" startups, warmed and listed on their own account, matched to the platform on name similarity alone. The tool says as much in its own caption: similarity is an investigative lead, not proof. The software vendors and universities in our results that came back as candidates with dozens of lookalikes each are a mix of the same thing and real impersonation, and the lookup doesn't tell you which is which.

This is where the design of the list cuts both ways. Heatwave attributes lookalike activity back to the domain being imitated, which is exactly how it catches a sales team's outreach tool. But the same mechanism means anyone can register example-team.com, warm it, run cold email from it, and example.com ends up as a candidate or worse, having done nothing. A spoofer's infrastructure and a victim's brand get tied together in the same lookup result. The same applies to two unrelated companies with similar names: if one runs warmup and cold outreach, the other can pick up the signal.
Validity's listing policy acknowledges all of this. Impersonation, unauthorized use, and "confusion between unrelated domains" are named as grounds for a review, and the review form has fields for third-party use and impersonation. So there is a path. But it runs in one direction: the listing happens automatically, and the victim has to find it, prove it, and wait two to five business days for a manual decision. For a large brand, a candidate result with a high lookalike count is an impersonation problem and needs DMARC enforcement and monitoring on the primary domain, not a warmup audit. For a small company, the lookalikes are usually theirs, registered by a tool nobody outside sales knew about.
Warmup listings don't expire, and there's no delisting for changed behavior
Three of the "warming" listings have a last-observed date weeks before the scan. One domain was last seen warming on July 29 and was still listed on September 10 with nothing new in between. That's by design.
Validity's listing policy says a synthetic-warming listing is a permanent historical observation that does not expire because the activity stopped or sending practices changed. The "active cold outreach" classification is different: it's a current state layered on top, and it can revert to warming-only if outreach is no longer observed. The base listing stays.

Removal comes only through a review request at lookup.validity.tools/delist, and only if Validity decides the original determination was wrong: misclassification, misattribution, impersonation, compromise, or confusion with an unrelated domain. Reviews are manual and typically take two to five business days. Stopping the warming and cleaning up your sending is not a ground for removal, and the policy says so in as many words. If the warming really happened, the domain carries the listing indefinitely.
Checking in bulk
The web lookup is capped at 100 queries per day per IP, and the public DNS resolver has been retired; DNS access is now a partner channel, an rsync feed of the bl.validity.tools zone that you serve from your own resolver. For anyone with that access, the answer encodes the verdict as 127.{age}.{score}.{stage}: the second octet is the observation age bucket (0 for under 7 days up to 4 for 180 days and over), the third is the relative score, the fourth is the stage (2 for warming, 3 for warming plus active outreach, 4 for pre-warming, meaning a registered sibling of a warming family that hasn't sent yet). 127.2.38.3 means observed 30 to 90 days ago, score band 38, cold outreach on top of warming. Lookups are exact-match; a subdomain of a listed domain is evaluated on its own.
What to do with a result
Listed or candidate on your primary domain: pull the lookalike list from the lookup and find out who registered each one and through which platform. Cancel the warmup subscriptions. Let the lookalikes lapse, or park the ones worth keeping with a p=reject DMARC policy and no mail flow, the same dormant-domain lockdown we applied across a 364-domain portfolio. If the primary domain itself was sending cold email, the fix is the same one we use for a SURBL listing: send to people who have a relationship with you, cut volume to what you can sustain, and strip anything from the content that reads as bulk unsolicited mail. Then check Spamhaus and SURBL directly, because that's where a Heatwave listing turns into a bounce. File a review request only if you can show the determination was wrong; a request that says "we stopped" will be declined on policy.
Clean domain, high lookalike count: that's impersonation, and changing how you send won't touch it. Enforce DMARC on the primary domain and monitor it, so at least the mail claiming to be you gets rejected.
The pattern across 1,055 domains was simple enough. The companies that priced the work and chose the warmup instead are the ones on the list.
SH Consulting works with companies whose sending reputation has been damaged by warming services, outreach tools, or infrastructure running under their brand without their knowledge. If your domain came back listed or as a candidate on Heatwave, or you have a Spamhaus or SURBL listing you can't explain, book a call.
Alex Shakhov is the founder of SH Consulting, an email security and deliverability consultancy. SH Consulting monitors DMARC for 1,300+ domains across 900+ companies.






