Author
Norbelys Chirinos
Co-founder of Norbelys. Writes on cold-email strategy, outreach that earns replies, and building an email product people can actually trust.
Articles by Norbelys Chirinos
80 articles
Compliance8 min
A new California deadline just made 'where did this list come from' a real question
California's Delete Act requires data brokers to honor bulk deletion requests from August 1, 2026 — a good moment to check where your list came from.
StrategyAnalysis9 min
How much of a CEO's day actually goes to email? Harvard tracked 27 of them to find out
Harvard tracked 27 CEOs for 13 weeks, 24/7. Electronic communication, mostly email, ate 24% of their time talking to people — more than every phone call combined.
ComplianceField note6 min
Apple's email-hiding feature leaked real addresses for over a year
A year-old bug in Apple's Hide My Email could expose a real address through a bounced message — a warning for anyone who treats bounces as harmless.
CopywritingAnalysis6 min
Do question subject lines actually get more opens, or is that just folklore?
The real psychology research on rhetorical questions in persuasion gives a more honest, more useful answer than the usual 'always ask a question' advice.
DeliverabilityAnalysis6 min
How many email addresses is the average professional actually juggling?
Worldwide, people carry 1.75 email accounts each on average in 2026 — and that ratio has been climbing for over a decade. Here's what's driving it.
Deliverability6 min
How much energy does sending one email actually use?
A single email costs a fraction of a gram of CO2 — until you multiply it by 361 billion sent per day. The real waste isn't email. It's mail nobody wanted.
ComplianceAnalysis7 min
Ireland's privacy regulator investigated 88% more marketing complaints last year
The Irish DPC's 2025 annual report shows a sharp jump in direct-marketing enforcement, including dozens of warning letters over unsolicited email and messaging.
Compliance7 min
Do you have to tell people they're talking to an AI? The EU's answer
From August 2, 2026, EU users must be told at the first message that they're talking to an AI. What counts as real disclosure, and what doesn't, concretely.
Deliverability8 min
"Delivered" doesn't mean anyone saw it. Here's the actual gap.
A 250 OK response only confirms a server accepted your message. Between that and a human actually reading it sit at least three more invisible steps.
DeliverabilityAnalysis9 min
Gmail, Outlook and Yahoo don't police bulk senders the same way in 2026
All three require SPF, DKIM and DMARC — but the tools they give senders to see their own reputation, and what those tools actually show, are three different systems.
DeliverabilityField note6 min
A password manager just got impersonated by a domain one letter off
LastPass warned customers about phishing sent from lookalike domains it never owned — a reminder that DMARC doesn't stop a domain that merely resembles yours.
DeliverabilityAnalysis8 min
Microsoft joined the bulk-sender rules in 2025 — and skipped straight to rejection
Google and Yahoo phased in bulk-sender enforcement gradually from 2024. Microsoft's 2025 rules skip straight to hard SMTP rejection — here's the real difference.
CopywritingAnalysis5 min
The line between AI personalization and AI impersonation just got official
The FTC's 2026 policy statement on deceptive AI and LinkedIn's crackdown draw the same line: AI is fine, fabricated claims aren't. Cold email sits on that line.
Deliverability8 min
Rejection, soft bounce, or spam folder: reading a 2026 delivery failure correctly
Gmail, Yahoo, and Microsoft fail mail differently now — a hard rejection, a reputation soft bounce, and silent spam-foldering each need a different fix.
ComplianceAnalysis6 min
The UK blocked 80 million spoofed emails a month. That's what enforcement, not adoption, looks like
National DMARC mandates cut phishing delivery from 69% to 14%. The UK blocked 80 million spoofed emails in 30 days — proof enforcement works.
DeliverabilityAnalysis5 min
An unauthenticated Exchange spoofing bug shows why DMARC and patching aren't the same control
CVE-2026-42897, an exploited XSS bug in Exchange OWA, ran JavaScript from one crafted email — client trust and transport auth are different controls.
ComplianceAnalysis8 min
A US state just cut its penalty for a misleading subject line by 80%
Washington's HB 2274 lowered CEMA's per-violation damages from $500 to $100, after a state Supreme Court ruling expanded what counts as a misleading subject line.
DeliverabilityAnalysis5 min
AI phishing jumped 14x in a month. Volume-based filtering can't keep up with that
Hoxhunt's 2026 data shows AI phishing going from 4% to 56% of reported attacks in a month, then settling near 40%. What breaks when growth outruns detection.
ComplianceAnalysis6 min
AI regulation isn't just the EU: where the major jurisdictions actually stand
The EU AI Act gets headlines, but South Korea's AI Basic Act, China's companion-AI rules, and a stalled US preemption fight all moved this month too.
DeliverabilityAnalysis8 min
Almost every bank has DMARC. Most still let spoofed email through
New 2026 reports show DMARC adoption is near-universal at banks, but only a minority enforce p=reject — the one setting that actually blocks spoofing.
ComplianceAnalysis5 min
Breach notification windows keep shrinking — 2026 made that concrete
California's SB 446 replaced a vague 'unreasonable delay' standard with a hard 30-day clock in 2026. Why fixed deadlines are becoming the norm for incident response.
ComplianceAnalysis6 min
The EU AI Act's enforcement phase just went live — here's what actually changed
July 10 activated real enforcement mechanics; August 2 hands the AI Office fining power over general-purpose models. What's binding now, and who it reaches.
Deliverability6 min
What changed in Google Postmaster Tools in 2026, and what to actually watch now
Postmaster Tools added a plain-language 'do users want your mail' verdict and a stricter spam-rate trigger. A guide to the new dashboard and what reputation means.
DeliverabilityAnalysis8 min
Over half a million domains are still at p=none. Is yours one of them?
The 2026 DMARC numbers show ~526,000 domains still parked at p=none. What that risks for the sender, not just the recipient, and how to leave it safely.
ComplianceAnalysis5 min
Phishing is now a $400-a-month subscription — what that does to defender economics
Forg365, a phishing-as-a-service platform targeting Microsoft 365, packages device-code phishing and session-token theft into a $400-a-month Telegram subscription.
ComplianceAnalysis6 min
'Rogue AI agents' is now its own cybersecurity category — and 'rogue' doesn't mean malicious
Forrester named rogue AI agents a top CISO risk for 2026. A July OpenAI/Hugging Face incident shows the term: an agent acting outside scope, no bad intent.
ProspectingAnalysis7 min
Stale contact data is a deliverability problem before it's a wasted-effort problem
2026 reporting flags verified data on a 7-day refresh as critical, because stale contacts bounce, and bounces damage sender reputation for every future campaign.
DeliverabilityAnalysis6 min
80% of phishing now uses AI content — so 'sounds AI-written' stopped being a tell
ENISA's Threat Landscape 2025 finds AI content in over 80% of observed phishing. What that means for detection, and why authentication is what's left standing.
ComplianceAnalysis7 min
The 2026 DMARC adoption numbers: 52.1% have a record, ~9% are actually protected
EasyDMARC's 2026 report puts DMARC adoption at 52.1% of top domains, up from 47.7% — but a record isn't protection. Here's what the enforcement gap means.
CopywritingAnalysis6 min
Does urgency in a cold email subject line actually work?
The real psychology behind scarcity and urgency language, why it works on shelves and often backfires in an inbox, and where the line actually is.
ComplianceAnalysis7 min
France just made 'did they open it' illegal to track without asking
France's CNIL closed its July 14 transition window for email tracking pixels — senders now need real consent to know who opened a message.
Deliverability8 min
Gmail reject vs. quarantine: what you actually see when compliance fails in 2026
Non-compliant bulk mail to Gmail can hit permanent rejection, temporary throttling, or silent spam-foldering — three failures that look nothing alike in your logs.
DeliverabilityAnalysis6 min
Why mailbox providers slow-walk mail from brand-new domains
A new domain and a spam operation's burner domain look identical on day one. That's the actual reason Gmail and Outlook cap what a new sender can send.
Strategy7 min
A tour of the Norbelys developer portal
REST API, OpenAPI spec, four SDKs, the CLI, and the MCP server — everything at norbelys.com/developers/, and where to start depending on what you're building.
Strategy5 min
How many times do you actually have to reach out before someone replies?
RAIN Group's benchmark puts it at 8 touches on average, 5 for top performers. What that number is really counting, and where email fits in it.
Deliverability8 min
Why plain-text emails still beat fancy HTML ones in cold outreach
A branded template signals 'campaign' to filters and humans alike. In cold outreach, the plainest-looking email is usually the one doing the least damage.
StrategyAnalysis7 min
Agencies: build white-label AI workflows on the Norbelys MCP server
One workspace per client solves the pricing problem. The MCP server solves another: how an agency builds its own tooling instead of reselling a vendor dashboard.
AI7 min
The guardrails an AI operator needs before it touches your sending domain
Rate limits, approval gates, and evidence requirements for letting an AI agent run cold email campaigns — and the signals that should never be fully automated.
Strategy7 min
Running cold email for multiple clients? One workspace per client, one flat bill
Agency cold email math breaks when tooling costs scale with every client. How a workspace-per-client model under one flat bill changes the day-to-day workflow.
StrategyAnalysis7 min
Norbelys for technical founders: script your outbound instead of clicking it
If you'd rather write a script than click a dashboard, the API, CLI, and SDKs are the real product. A case for solo founders running their own outbound.
StrategyAnalysis8 min
The state of cold email in 2026: what actually changed
Sender-rule enforcement got teeth, Gmail's spam classifier got upgraded, and AI drafting went mainstream — a grounded look at what changed in cold email this year.
Strategy7 min
Switching from Smartlead to Norbelys: what to export, what maps, what changes
Smartlead is a genuine volume machine. If honest analytics or a flatter bill are why you're leaving, here's the practical migration checklist.
AIAnalysis8 min
AI is reading your cold email before the recipient does. Here's what's actually shipped.
Gmail's Gemini and Outlook's Copilot thread summaries are live in 2026. What that changes about subject lines and preview text — and what's still speculation.
AIAnalysis7 min
AI SDRs vs. human judgment: what to actually automate in cold email
AI speeds up research, drafting, and list coordination in cold email. Relevance judgment, relationship nuance, and the final send still belong to a human.
StrategyAnalysis7 min
API-first vs. UI-first: what you actually give up with a click-only cold-email tool
The strategic case for API-first cold-email tools: scriptability, CI integration, custom tooling, and why the UI and the API should never be two different lists.
Deliverability6 min
DMARC monitoring for agencies: one client's XML is manageable, twenty isn't
Running cold email or deliverability for many client domains means DMARC visibility across all of them at once. Why per-client XML doesn't scale.
Strategy7 min
Every Norbelys integration, and what it actually does
Slack, HubSpot, Pipedrive, Salesforce and Calendly — what each live Norbelys integration actually does today, plus the honest note on what's still on the way.
StrategyAnalysis7 min
Why developers pick Norbelys: the API-first case, with receipts
Not 'developers love APIs' — the specific, checkable reasons a technical buyer picks Norbelys: one contract, 83 operations, four SDKs, a CLI, and MCP.
StrategyAnalysis8 min
Why we built a CLI for cold email
Most cold-email platforms are pure dashboards with no command line at all. Here's the actual case for shipping one anyway, and exactly who it benefits.
AI6 min
How to prompt AI for cold email that doesn't sound like AI
A practical guide to prompting AI for cold email that reads as researched, not generic — specificity, constraints, real detail, and the stock phrases to ban.
StrategyAnalysis7 min
Why your 40th email today gets judged differently than your 4th
Real research on decision fatigue — from parole judges to online shoppers — and what it means for when a cold email lands, not just what it says.
Deliverability7 min
DMARC forensic reports (ruf): what they are, and why almost nobody sends them
The ruf tag asks for a copy of every failing message. What forensic reports contain, why most mailbox providers stopped sending them, and when to bother.
CopywritingAnalysis9 min
Does a joke in a cold email actually help, or just feel like it does?
A fair look at what the actual research on humor and persuasion says, where a joke helps a cold email and where the same joke quietly costs you the reply.
Strategy8 min
Sending from Apollo? Here's what changes if you route sends through Norbelys
Apollo is a data platform, not a delivery one. A practical guide to keeping Apollo for sourcing while routing the actual sending through Norbelys instead.
Strategy8 min
Switching from Lemlist to Norbelys: a practical migration guide
Leaving Lemlist because email is your real bottleneck? What to export, what maps to what, and what changes — including an honest look at where Lemlist still wins.
Deliverability5 min
What actually happens in the seconds after you hit send
Between your click and the recipient's inbox: a DNS lookup, a handshake with a stranger's server, and a filter deciding your fate — all in under two seconds.
Deliverability7 min
Why the same email looks different in Gmail, Outlook, and Apple Mail
Gmail, Outlook desktop, and Apple Mail don't share a rendering engine. One of them literally uses Microsoft Word — and that changes what you should design.
DeliverabilityField note5 min
Yahoo added a one-tap unsubscribe button. It changes what your numbers mean
Yahoo's July 2026 update put unsubscribing one tap away, directly in the inbox. For senders, that reshapes what a rising unsubscribe rate actually signals.
AIAnalysis8 min
When an AI reads your email for them: what 'open rate' even means now
AI summarizers are becoming a real first reader in Gmail and Outlook — what's documented about zero-click inboxes and what it means for open and reply metrics.
CopywritingAnalysis5 min
The most-read line in your cold email might be the one you never plan
Direct-mail research says the postscript gets read almost first, not last. What a good P.S. line actually does, with real before/after examples.
ProspectingAnalysis8 min
Where your prospect lives changes your cold email reply rate more than you'd think
A 7.5-million-email 2025 study found reply rates from 1.43% in Poland to 0.51% in the US — geography alone nearly tripled the number. Here's why.
Deliverability7 min
How a sending domain actually ends up on a blocklist
Not a single bad email. Blocklisting is almost always one of four repeatable triggers: trap hits, complaint-rate crossings, volume anomalies, or borrowed reputation.
DeliverabilityAnalysis7 min
What actually happens inside a spam filter before your email arrives
A spam filter isn't one gate reading your words and voting. It's three systems — identity, content and collective memory — scoring you in real time.
DeliverabilityAnalysis9 min
A new standard could finally show you where your cold email actually lands
A proposed IETF spec called APRF would have mailbox providers report placement and engagement data back to senders, the way DMARC reports authentication failures.
DeliverabilityField note6 min
AOL Mail has a new owner. Here's what that means if you still send to it
Bending Spoons closed its acquisition of AOL from Yahoo in early 2026. AOL Mail still has tens of millions of users — here's what's known and unknown for senders.
Deliverability6 min
The pre-send cold email checklist: four gates, sixteen checks
Run every campaign through four gates before it sends: domain, list, copy, send settings. Sixteen checks, each with the free tool that verifies it.
Copywriting7 min
Personalization at scale: the ladder from {first_name} to 18% replies
Merge fields aren't personalization, they're mail merge. The four rungs of the personalization ladder, what each costs, and the reply rate at each.
Strategy6 min
The AI campaign brief that gets usable cold email instead of sludge
AI can draft cold email, but only if the brief gives it ICP, trigger, offer, proof, constraints and approval rules. Here is the Norbelys-style brief and workflow.
Strategy8 min
Cold calling vs. cold email: the honest math, not the holy war
Cost per conversation, cost per meeting, and what each channel actually wins at: dials cap around 60-80 a day, email compounds while you sleep.
Strategy6 min
Cold email A/B testing: why your winner is usually too early
Most cold email tests call winners on tiny samples and noisy reply rates. The sample-size math, the metric to trust, and how Norbelys tests on human outcomes.
Copywriting7 min
Cold email templates that still work in 2026 — with the anatomy that makes them work
Eight cold email templates by scenario, plus the five-part anatomy behind every one. Under 100 words each, no fake personalization, built for the 0.3% complaint era.
Strategy5 min
When prospects actually reply to cold email — and why your reply speed matters more
Most replies land in the first few hours, then a long tail. The stat with real money behind it: fastest vendor wins ~50% of deals; replying in 5 minutes helps 21×.
Strategy6 min
Built on U.S. anti-spam law: how Norbelys keeps you legal
Norbelys is a U.S. company built around CAN-SPAM and the CCPA. What those laws require, the mailbox-provider rules on top, and how the platform enforces every line.
Deliverability5 min
The 0.3% line: how spam complaints decide your sender reputation
Gmail and Yahoo enforce a hard 0.3% spam-complaint ceiling, 30 per 10,000 emails. The real math on how fast one bad send moves the needle, and how to stay under it.
Strategy6 min
Cold email benchmarks for 2026 that survive contact with reality
Real numbers from 20M+ and 12M email studies on delivery, opens, replies. Why open rate is mostly Apple's robots, and how personalization swings replies 1% to 18%.
StrategyField note7 min
Our domain is 11 days old. Here's exactly how we're sending from it.
A build-in-public deliverability diary: the records we set on day one, the warmup ramp we're on, and the receipts you can check yourself on our own domain.
Prospecting6 min
How to find (almost) anyone's business email — without paying for it
Most companies use one of 14 address patterns. The free permute-and-verify workflow, the catch-all trap that fakes success, and the line you shouldn't cross.
Strategy6 min
Cold email math: what 1,000 sends honestly turns into
Work the funnel backwards — sends, deliveries, real opens, replies, meetings — with honest numbers at every stage, and see why list quality beats raw volume.
Strategy6 min
How many cold emails per day per mailbox? Fewer than you want.
The honest per-mailbox ceiling in 2026, why the 5,000-a-day bulk-sender line is a tripwire and not a target, and how to scale volume without burning domains.
Copywriting6 min
How to write a cold email that gets replies (not just opens)
The anatomy of a reply-worthy cold email: a first line that proves homework, one problem, one proof point, one ask, and follow-up rules that don't burn goodwill.