Apollo account audit: 15 checks to run before you send another cold email

WORKSHOP

Workshop 32: Apollo account audit: 15 checks to run before you send another cold email

Outbound accounts drift quietly. A campaign sits active for weeks sending nothing, cold email goes out from the company's main domain, and a website tracker is installed without ever receiving data. None of it shows up until someone looks.

On the first real account this audit was run on, it found all three in under an hour. The one that costs most is the stuck campaign: five contacts enrolled, zero emails scheduled in two weeks, and all six emails waiting for approval. In any report it looks like dead copy or a bad list, so the natural response is to rewrite something that was never sent.

Use this before anything else runs on an account you inherited, took over from an agency, or have not opened in a while.

What it does

The prompt runs 15 checks in a set order, because the early ones explain the later ones: access, mailboxes, daily limits, domain authentication, live campaigns, bounce auto-pause, history, idle campaigns, lists, contacts, credits, stored business context, website tracking, send schedules, and compliance. Each area gets a grade of Good, Watch, or Fix with one line of evidence. You finish with what to fix first, what to watch, what to tidy, the three most important actions in order, and what the audit could not see. It changes nothing: connected to the platform it uses reads only, and every fix waits for you.

What it catches

  • Campaigns that look live and send nothing. Emails waiting for review. Check approval status before diagnosing copy, lists, or email deliverability.

  • Cold email from the primary domain or free mail. Both are a Fix, whatever the current volume.

  • Daily limits above the ceiling. Up to 25 cold sends per mailbox per day. One platform's analytics reported a limit of 775 for a mailbox set to 25, so limits get read from the mailbox settings.

  • An auto-pause that never fires. One platform's bounce auto-pause does not evaluate until a campaign has sent 200 emails in seven days, so small and new campaigns are never protected.

  • Bounce rates hidden by summaries. Anything above 4%, taken from contact-level statuses. One analytics count showed six bounces where the contacts showed zero. Archived campaigns are included.

  • Stale authentication results. SPF, DKIM, and DMARC checks are usually the last stored result, so the date gets read first.

  • Duplicates from bulk uploads. A sample of the newest few hundred contacts, since uploads may not deduplicate.

  • Credit pools at zero. Credits are usually several separate pools, so every finding names the pool.

How to use it

Pick whichever route fits your setup.

  1. Paste it into a chat. Copy the prompt below into ChatGPT, Claude, or any other assistant, and it gives you a list of what to open and note.

  2. Add it to a Claude Project. Upload it as a Project file. Connect Apollo and it runs the checks itself, read-only: the Claude setup guide.

The prompt

Copy the whole prompt below, from the first line to the last.

You are auditing a prospecting and sending account I did not build, or have not looked at in a while, before anything else runs on it. Find out what state it is in and hand me graded findings. The audit changes nothing: every fix waits for me.

Accounts drift quietly. A campaign can sit active for weeks sending nothing, cold email can go out from the company's main domain, and a website tracker can be installed without ever receiving data. None of it shows until someone looks. On the first real account this was run on, it found all three in under an hour.

If the platform is connected as a tool, run the checks yourself using reads only. Do not approve, archive, delete, change a limit, or edit a list, however obvious the fix looks. If nothing is connected, give me the checks as a list of what to open and what to note, then grade what I bring back.

You advise and I decide. Deliverability findings are the one place to be firm.

Run the checks in this order, since the early ones explain the later ones. Grade each area Good, Watch, or Fix.

  1. Access and team. Who is on the account, and whether you are reading it as the right user.

  2. Mailboxes. Sending cold email from the company's primary domain is a Fix. So is a free-mail address.

  3. Daily limits. Each mailbox's configured daily cap, hourly cap, delay between emails, and warmup state. Up to 25 cold sends per mailbox per day is the ceiling. A limit far above it is a Fix even when volume is low today. Read the limit from the mailbox settings, not from a reporting metric: on one platform, analytics reported a daily limit of 775 for a mailbox set to 25.

  4. Domain authentication. SPF, DKIM, and DMARC results for each sending domain. Read the date of the check first: it is usually the last stored result, not a live one.

  5. Live campaigns. For each active campaign, what is enrolled and what is actually scheduled. An active campaign with contacts and nothing scheduled is the finding to catch (see below).

  6. Bounce auto-pause. Whether it is on for each campaign, its thresholds, and its minimum volume against the campaign's real volume. Every auto-pause has a minimum volume. One platform's auto-pause does not evaluate at all until a campaign has sent 200 emails inside its seven-day window, so a small or new campaign is never protected, however badly it bounces.

  7. Performance history. Any campaign with a real bounce rate above 4%, taken from the contact-level bounce statuses rather than a summary metric (one analytics bounce count showed six where the contacts showed zero). Include archived campaigns: they keep their history in reporting and can vanish from the campaign list.

  8. Idle and test campaigns. Inactive tests and abandoned drafts. Clutter, not risk, but a sign nobody owns the account.

  9. Lists. How many, which are empty, how old, which are tests.

  10. Contacts. The total, then a duplicate sample: sort by date created, pull a few hundred of the newest, and count repeated emails. Bulk uploads may not deduplicate, so recent uploads are where duplicates hide.

  11. Credits. Any pool at zero, and whether the contact data pool covers the next planned list. Credits are usually several separate pools, so always name the pool.

  12. Stored business context. If the platform keeps a profile of the business for its AI features, whether it is set up and still matches the business.

  13. Website tracking. Installed but receiving no data means the script is not live. Also whether person-level identification is possible or only company-level.

  14. Send schedules. The send window and timezone against the policy I run to.

  15. Compliance. Whether prospecting in regions with stricter privacy rules is blocked or allowed, against the countries I target. Unsubscribe counts and opt-out rate. Whether phone numbers are screened against do-not-call lists. If the unsubscribe link setting cannot be read, list it as a manual check.

The finding that looks like a performance problem and is not. A campaign can be active, with contacts enrolled, and send nothing because its emails are waiting for approval. On one real account, an active campaign with five enrolled contacts had scheduled zero emails in two weeks, and every one of its six emails was marked as waiting for review. It reads as a dead campaign in any report. Check approval status before diagnosing copy, lists, or deliverability. Approving starts real email, so report it and stop.

Say what the audit cannot see, so a clean audit is not read as a clean bill of health:

- Mailboxes and domains connected to a different sending platform.

- Blacklists and inbox placement.

- Reply text, beyond counts and categories.

- Anything the connected access level cannot reach.

- Team-wide settings changed in the interface, beyond what each campaign reports.


Privacy. An audit of someone else's account is full of their data: prospects, list names, campaign names, results. Keep the output with that account, never in anything shared or published, and describe findings by pattern when discussing them elsewhere.

What to hand me at the end:

- Every area with its grade and one line of evidence.

- Fix first: anything sending unsafely, or sending nothing while looking live. - Watch: fine today, not tomorrow. A limit above the ceiling, an auto-pause that never evaluates at this volume, credits that will not cover the next list. - Tidy: test campaigns, empty lists, stale business context.

- The three actions that matter most, in order, and what each needs from me.

- What the audit could not see.


Method adapted from the account audit in Apollo Operator, a free, open-source headless GTM toolkit by Creatop: github.com/creatop-gtm/apollo-operator

Part of the Apollo Operator prompt pack

This is one of 19 free prompts from Apollo Operator, the open-source headless GTM toolkit Creatop builds and runs on its own campaigns. Get the full pack here: the Apollo Operator prompt pack.

LATEST

FEATURED

Learn from our work

Logo

OUR NEWSLETTER

Notes from live campaigns. No theory, no filler.

PAGES

MORE

LEGAL

© 2026 Creatop. All rights reserved.

Learn from our work

Logo

OUR NEWSLETTER

Notes from live campaigns. No theory, no filler.

PAGES

MORE

LEGAL

© 2026 Creatop. All rights reserved.

Learn from our work

Logo

OUR NEWSLETTER

Notes from live campaigns. No theory, no filler.

PAGES

MORE

LEGAL

© 2026 Creatop. All rights reserved.