Skip to content

Author

Norbelys Chirinos

Co-founder of Norbelys. Writes on cold-email strategy, outreach that earns replies, and building an email product people can actually trust.

Co-founder at Norbelys

  • Cold-email strategy
  • Copywriting
  • Product operations

Articles by Norbelys Chirinos

80 articles

Compliance8 min

A new California deadline just made 'where did this list come from' a real question

California's Delete Act requires data brokers to honor bulk deletion requests from August 1, 2026 — a good moment to check where your list came from.

StrategyAnalysis9 min

How much of a CEO's day actually goes to email? Harvard tracked 27 of them to find out

Harvard tracked 27 CEOs for 13 weeks, 24/7. Electronic communication, mostly email, ate 24% of their time talking to people — more than every phone call combined.

ComplianceField note6 min

Apple's email-hiding feature leaked real addresses for over a year

A year-old bug in Apple's Hide My Email could expose a real address through a bounced message — a warning for anyone who treats bounces as harmless.

CopywritingAnalysis6 min

Do question subject lines actually get more opens, or is that just folklore?

The real psychology research on rhetorical questions in persuasion gives a more honest, more useful answer than the usual 'always ask a question' advice.

DeliverabilityAnalysis6 min

How many email addresses is the average professional actually juggling?

Worldwide, people carry 1.75 email accounts each on average in 2026 — and that ratio has been climbing for over a decade. Here's what's driving it.

Deliverability6 min

How much energy does sending one email actually use?

A single email costs a fraction of a gram of CO2 — until you multiply it by 361 billion sent per day. The real waste isn't email. It's mail nobody wanted.

ComplianceAnalysis7 min

Ireland's privacy regulator investigated 88% more marketing complaints last year

The Irish DPC's 2025 annual report shows a sharp jump in direct-marketing enforcement, including dozens of warning letters over unsolicited email and messaging.

Compliance7 min

Do you have to tell people they're talking to an AI? The EU's answer

From August 2, 2026, EU users must be told at the first message that they're talking to an AI. What counts as real disclosure, and what doesn't, concretely.

Deliverability8 min

"Delivered" doesn't mean anyone saw it. Here's the actual gap.

A 250 OK response only confirms a server accepted your message. Between that and a human actually reading it sit at least three more invisible steps.

DeliverabilityAnalysis9 min

Gmail, Outlook and Yahoo don't police bulk senders the same way in 2026

All three require SPF, DKIM and DMARC — but the tools they give senders to see their own reputation, and what those tools actually show, are three different systems.

DeliverabilityField note6 min

A password manager just got impersonated by a domain one letter off

LastPass warned customers about phishing sent from lookalike domains it never owned — a reminder that DMARC doesn't stop a domain that merely resembles yours.

DeliverabilityAnalysis8 min

Microsoft joined the bulk-sender rules in 2025 — and skipped straight to rejection

Google and Yahoo phased in bulk-sender enforcement gradually from 2024. Microsoft's 2025 rules skip straight to hard SMTP rejection — here's the real difference.

CopywritingAnalysis5 min

The line between AI personalization and AI impersonation just got official

The FTC's 2026 policy statement on deceptive AI and LinkedIn's crackdown draw the same line: AI is fine, fabricated claims aren't. Cold email sits on that line.

Deliverability8 min

Rejection, soft bounce, or spam folder: reading a 2026 delivery failure correctly

Gmail, Yahoo, and Microsoft fail mail differently now — a hard rejection, a reputation soft bounce, and silent spam-foldering each need a different fix.

ComplianceAnalysis6 min

The UK blocked 80 million spoofed emails a month. That's what enforcement, not adoption, looks like

National DMARC mandates cut phishing delivery from 69% to 14%. The UK blocked 80 million spoofed emails in 30 days — proof enforcement works.

DeliverabilityAnalysis5 min

An unauthenticated Exchange spoofing bug shows why DMARC and patching aren't the same control

CVE-2026-42897, an exploited XSS bug in Exchange OWA, ran JavaScript from one crafted email — client trust and transport auth are different controls.

ComplianceAnalysis8 min

A US state just cut its penalty for a misleading subject line by 80%

Washington's HB 2274 lowered CEMA's per-violation damages from $500 to $100, after a state Supreme Court ruling expanded what counts as a misleading subject line.

DeliverabilityAnalysis5 min

AI phishing jumped 14x in a month. Volume-based filtering can't keep up with that

Hoxhunt's 2026 data shows AI phishing going from 4% to 56% of reported attacks in a month, then settling near 40%. What breaks when growth outruns detection.

ComplianceAnalysis6 min

AI regulation isn't just the EU: where the major jurisdictions actually stand

The EU AI Act gets headlines, but South Korea's AI Basic Act, China's companion-AI rules, and a stalled US preemption fight all moved this month too.

DeliverabilityAnalysis8 min

Almost every bank has DMARC. Most still let spoofed email through

New 2026 reports show DMARC adoption is near-universal at banks, but only a minority enforce p=reject — the one setting that actually blocks spoofing.

ComplianceAnalysis5 min

Breach notification windows keep shrinking — 2026 made that concrete

California's SB 446 replaced a vague 'unreasonable delay' standard with a hard 30-day clock in 2026. Why fixed deadlines are becoming the norm for incident response.

ComplianceAnalysis6 min

The EU AI Act's enforcement phase just went live — here's what actually changed

July 10 activated real enforcement mechanics; August 2 hands the AI Office fining power over general-purpose models. What's binding now, and who it reaches.

Deliverability6 min

What changed in Google Postmaster Tools in 2026, and what to actually watch now

Postmaster Tools added a plain-language 'do users want your mail' verdict and a stricter spam-rate trigger. A guide to the new dashboard and what reputation means.

DeliverabilityAnalysis8 min

Over half a million domains are still at p=none. Is yours one of them?

The 2026 DMARC numbers show ~526,000 domains still parked at p=none. What that risks for the sender, not just the recipient, and how to leave it safely.

ComplianceAnalysis5 min

Phishing is now a $400-a-month subscription — what that does to defender economics

Forg365, a phishing-as-a-service platform targeting Microsoft 365, packages device-code phishing and session-token theft into a $400-a-month Telegram subscription.

ComplianceAnalysis6 min

'Rogue AI agents' is now its own cybersecurity category — and 'rogue' doesn't mean malicious

Forrester named rogue AI agents a top CISO risk for 2026. A July OpenAI/Hugging Face incident shows the term: an agent acting outside scope, no bad intent.

ProspectingAnalysis7 min

Stale contact data is a deliverability problem before it's a wasted-effort problem

2026 reporting flags verified data on a 7-day refresh as critical, because stale contacts bounce, and bounces damage sender reputation for every future campaign.

DeliverabilityAnalysis6 min

80% of phishing now uses AI content — so 'sounds AI-written' stopped being a tell

ENISA's Threat Landscape 2025 finds AI content in over 80% of observed phishing. What that means for detection, and why authentication is what's left standing.

ComplianceAnalysis7 min

The 2026 DMARC adoption numbers: 52.1% have a record, ~9% are actually protected

EasyDMARC's 2026 report puts DMARC adoption at 52.1% of top domains, up from 47.7% — but a record isn't protection. Here's what the enforcement gap means.

CopywritingAnalysis6 min

Does urgency in a cold email subject line actually work?

The real psychology behind scarcity and urgency language, why it works on shelves and often backfires in an inbox, and where the line actually is.

ComplianceAnalysis7 min

France just made 'did they open it' illegal to track without asking

France's CNIL closed its July 14 transition window for email tracking pixels — senders now need real consent to know who opened a message.

Deliverability8 min

Gmail reject vs. quarantine: what you actually see when compliance fails in 2026

Non-compliant bulk mail to Gmail can hit permanent rejection, temporary throttling, or silent spam-foldering — three failures that look nothing alike in your logs.

DeliverabilityAnalysis6 min

Why mailbox providers slow-walk mail from brand-new domains

A new domain and a spam operation's burner domain look identical on day one. That's the actual reason Gmail and Outlook cap what a new sender can send.

Strategy7 min

A tour of the Norbelys developer portal

REST API, OpenAPI spec, four SDKs, the CLI, and the MCP server — everything at norbelys.com/developers/, and where to start depending on what you're building.

Strategy5 min

How many times do you actually have to reach out before someone replies?

RAIN Group's benchmark puts it at 8 touches on average, 5 for top performers. What that number is really counting, and where email fits in it.

Deliverability8 min

Why plain-text emails still beat fancy HTML ones in cold outreach

A branded template signals 'campaign' to filters and humans alike. In cold outreach, the plainest-looking email is usually the one doing the least damage.

StrategyAnalysis7 min

Agencies: build white-label AI workflows on the Norbelys MCP server

One workspace per client solves the pricing problem. The MCP server solves another: how an agency builds its own tooling instead of reselling a vendor dashboard.

AI7 min

The guardrails an AI operator needs before it touches your sending domain

Rate limits, approval gates, and evidence requirements for letting an AI agent run cold email campaigns — and the signals that should never be fully automated.

Strategy7 min

Running cold email for multiple clients? One workspace per client, one flat bill

Agency cold email math breaks when tooling costs scale with every client. How a workspace-per-client model under one flat bill changes the day-to-day workflow.

StrategyAnalysis7 min

Norbelys for technical founders: script your outbound instead of clicking it

If you'd rather write a script than click a dashboard, the API, CLI, and SDKs are the real product. A case for solo founders running their own outbound.

StrategyAnalysis8 min

The state of cold email in 2026: what actually changed

Sender-rule enforcement got teeth, Gmail's spam classifier got upgraded, and AI drafting went mainstream — a grounded look at what changed in cold email this year.

Strategy7 min

Switching from Smartlead to Norbelys: what to export, what maps, what changes

Smartlead is a genuine volume machine. If honest analytics or a flatter bill are why you're leaving, here's the practical migration checklist.

AIAnalysis8 min

AI is reading your cold email before the recipient does. Here's what's actually shipped.

Gmail's Gemini and Outlook's Copilot thread summaries are live in 2026. What that changes about subject lines and preview text — and what's still speculation.

AIAnalysis7 min

AI SDRs vs. human judgment: what to actually automate in cold email

AI speeds up research, drafting, and list coordination in cold email. Relevance judgment, relationship nuance, and the final send still belong to a human.

StrategyAnalysis7 min

API-first vs. UI-first: what you actually give up with a click-only cold-email tool

The strategic case for API-first cold-email tools: scriptability, CI integration, custom tooling, and why the UI and the API should never be two different lists.

Deliverability6 min

DMARC monitoring for agencies: one client's XML is manageable, twenty isn't

Running cold email or deliverability for many client domains means DMARC visibility across all of them at once. Why per-client XML doesn't scale.

Strategy7 min

Every Norbelys integration, and what it actually does

Slack, HubSpot, Pipedrive, Salesforce and Calendly — what each live Norbelys integration actually does today, plus the honest note on what's still on the way.

StrategyAnalysis7 min

Why developers pick Norbelys: the API-first case, with receipts

Not 'developers love APIs' — the specific, checkable reasons a technical buyer picks Norbelys: one contract, 83 operations, four SDKs, a CLI, and MCP.

StrategyAnalysis8 min

Why we built a CLI for cold email

Most cold-email platforms are pure dashboards with no command line at all. Here's the actual case for shipping one anyway, and exactly who it benefits.

AI6 min

How to prompt AI for cold email that doesn't sound like AI

A practical guide to prompting AI for cold email that reads as researched, not generic — specificity, constraints, real detail, and the stock phrases to ban.

StrategyAnalysis7 min

Why your 40th email today gets judged differently than your 4th

Real research on decision fatigue — from parole judges to online shoppers — and what it means for when a cold email lands, not just what it says.

Deliverability7 min

DMARC forensic reports (ruf): what they are, and why almost nobody sends them

The ruf tag asks for a copy of every failing message. What forensic reports contain, why most mailbox providers stopped sending them, and when to bother.

CopywritingAnalysis9 min

Does a joke in a cold email actually help, or just feel like it does?

A fair look at what the actual research on humor and persuasion says, where a joke helps a cold email and where the same joke quietly costs you the reply.

Strategy8 min

Sending from Apollo? Here's what changes if you route sends through Norbelys

Apollo is a data platform, not a delivery one. A practical guide to keeping Apollo for sourcing while routing the actual sending through Norbelys instead.

Strategy8 min

Switching from Lemlist to Norbelys: a practical migration guide

Leaving Lemlist because email is your real bottleneck? What to export, what maps to what, and what changes — including an honest look at where Lemlist still wins.

Deliverability5 min

What actually happens in the seconds after you hit send

Between your click and the recipient's inbox: a DNS lookup, a handshake with a stranger's server, and a filter deciding your fate — all in under two seconds.

Deliverability7 min

Why the same email looks different in Gmail, Outlook, and Apple Mail

Gmail, Outlook desktop, and Apple Mail don't share a rendering engine. One of them literally uses Microsoft Word — and that changes what you should design.

DeliverabilityField note5 min

Yahoo added a one-tap unsubscribe button. It changes what your numbers mean

Yahoo's July 2026 update put unsubscribing one tap away, directly in the inbox. For senders, that reshapes what a rising unsubscribe rate actually signals.

AIAnalysis8 min

When an AI reads your email for them: what 'open rate' even means now

AI summarizers are becoming a real first reader in Gmail and Outlook — what's documented about zero-click inboxes and what it means for open and reply metrics.

CopywritingAnalysis5 min

The most-read line in your cold email might be the one you never plan

Direct-mail research says the postscript gets read almost first, not last. What a good P.S. line actually does, with real before/after examples.

ProspectingAnalysis8 min

Where your prospect lives changes your cold email reply rate more than you'd think

A 7.5-million-email 2025 study found reply rates from 1.43% in Poland to 0.51% in the US — geography alone nearly tripled the number. Here's why.

Deliverability7 min

How a sending domain actually ends up on a blocklist

Not a single bad email. Blocklisting is almost always one of four repeatable triggers: trap hits, complaint-rate crossings, volume anomalies, or borrowed reputation.

DeliverabilityAnalysis7 min

What actually happens inside a spam filter before your email arrives

A spam filter isn't one gate reading your words and voting. It's three systems — identity, content and collective memory — scoring you in real time.

DeliverabilityAnalysis9 min

A new standard could finally show you where your cold email actually lands

A proposed IETF spec called APRF would have mailbox providers report placement and engagement data back to senders, the way DMARC reports authentication failures.

DeliverabilityField note6 min

AOL Mail has a new owner. Here's what that means if you still send to it

Bending Spoons closed its acquisition of AOL from Yahoo in early 2026. AOL Mail still has tens of millions of users — here's what's known and unknown for senders.

Deliverability6 min

The pre-send cold email checklist: four gates, sixteen checks

Run every campaign through four gates before it sends: domain, list, copy, send settings. Sixteen checks, each with the free tool that verifies it.

Copywriting7 min

Personalization at scale: the ladder from {first_name} to 18% replies

Merge fields aren't personalization, they're mail merge. The four rungs of the personalization ladder, what each costs, and the reply rate at each.

Strategy6 min

The AI campaign brief that gets usable cold email instead of sludge

AI can draft cold email, but only if the brief gives it ICP, trigger, offer, proof, constraints and approval rules. Here is the Norbelys-style brief and workflow.

Strategy8 min

Cold calling vs. cold email: the honest math, not the holy war

Cost per conversation, cost per meeting, and what each channel actually wins at: dials cap around 60-80 a day, email compounds while you sleep.

Strategy6 min

Cold email A/B testing: why your winner is usually too early

Most cold email tests call winners on tiny samples and noisy reply rates. The sample-size math, the metric to trust, and how Norbelys tests on human outcomes.

Copywriting7 min

Cold email templates that still work in 2026 — with the anatomy that makes them work

Eight cold email templates by scenario, plus the five-part anatomy behind every one. Under 100 words each, no fake personalization, built for the 0.3% complaint era.

Strategy5 min

When prospects actually reply to cold email — and why your reply speed matters more

Most replies land in the first few hours, then a long tail. The stat with real money behind it: fastest vendor wins ~50% of deals; replying in 5 minutes helps 21×.

Strategy6 min

Built on U.S. anti-spam law: how Norbelys keeps you legal

Norbelys is a U.S. company built around CAN-SPAM and the CCPA. What those laws require, the mailbox-provider rules on top, and how the platform enforces every line.

Deliverability5 min

The 0.3% line: how spam complaints decide your sender reputation

Gmail and Yahoo enforce a hard 0.3% spam-complaint ceiling, 30 per 10,000 emails. The real math on how fast one bad send moves the needle, and how to stay under it.

Strategy6 min

Cold email benchmarks for 2026 that survive contact with reality

Real numbers from 20M+ and 12M email studies on delivery, opens, replies. Why open rate is mostly Apple's robots, and how personalization swings replies 1% to 18%.

StrategyField note7 min

Our domain is 11 days old. Here's exactly how we're sending from it.

A build-in-public deliverability diary: the records we set on day one, the warmup ramp we're on, and the receipts you can check yourself on our own domain.

Prospecting6 min

How to find (almost) anyone's business email — without paying for it

Most companies use one of 14 address patterns. The free permute-and-verify workflow, the catch-all trap that fakes success, and the line you shouldn't cross.

Strategy6 min

Cold email math: what 1,000 sends honestly turns into

Work the funnel backwards — sends, deliveries, real opens, replies, meetings — with honest numbers at every stage, and see why list quality beats raw volume.

Strategy6 min

How many cold emails per day per mailbox? Fewer than you want.

The honest per-mailbox ceiling in 2026, why the 5,000-a-day bulk-sender line is a tripwire and not a target, and how to scale volume without burning domains.

Copywriting6 min

How to write a cold email that gets replies (not just opens)

The anatomy of a reply-worthy cold email: a first line that proves homework, one problem, one proof point, one ask, and follow-up rules that don't burn goodwill.