What you actually see when your DMARC report shows up in Norbelys
Not raw XML — a domain view with every sending source, pass rates, and a plain-language fix. Here's what the dashboard looks like on day one and month three.
By David Lara, Founder
Founder-reviewed ·How we research and correct articles
Somewhere between adding a DMARC record and actually understanding your domain’s authentication status sits a folder full of gzipped XML files that almost nobody opens. Gmail, Outlook and Yahoo all send them daily once you’re set up to receive reports — and almost none of that data is human readable without processing it first. This isn’t another explainer on what DMARC does or how to read the raw reports by hand — those exist and cover the protocol well. This is what shows up on your screen once Norbelys is doing that processing for you.
Day one: waiting, then collecting
After you add the domain and merge Norbelys’s reporting address into your
DMARC record’s rua field, the domain view starts in a waiting state —
there’s nothing to show yet because no receiver has sent a report. That
usually changes within a day, sometimes faster: the first aggregate digest
arrives from whichever mailbox provider processes your mail soonest, and the
status flips from waiting to collecting. From that point the view fills in
gradually as more providers report, typically settling into a complete
picture across a full reporting cycle rather than all at once.
Getting reports flowing in the first place
The setup itself is a DNS change, not a product configuration screen full of settings to get right:
From adding a domain to a readable view
Add the domain
Enter the sending domain in the workspace. Norbelys generates a reporting address scoped to that domain.
Publish or merge the rua record
Add the provided address to your DMARC TXT record's rua field — merge it in alongside any existing reporting address rather than replacing it, if you already have one.
Reports start arriving
Aggregate XML begins landing from participating mailbox providers, usually within a day of the record propagating.
Read and act from the domain view
Sources, pass rate, alignment and named findings are already parsed and waiting — no XML to open by hand.
What the domain view actually shows
Once reports are flowing, the page you land on isn’t a report — it’s a running answer to “who is sending mail as my domain, and is it landing clean.” Every source that’s touched your domain in the reporting window shows up as its own row, whether that’s your own outbound infrastructure, a known transactional service, or something you’ve never heard of:
| Source | Volume | SPF | DKIM | Compliance |
|---|---|---|---|---|
| Google Workspace | 9,824 | 100% | 99.9% | 99.9% |
| SendGrid (known service) | 2,907 | 100% | 98.1% | 98.4% |
| 185.17.4.21 (unidentified) | 115 | 0% | 0% | 0% |
The unidentified row is the one worth stopping on. That’s not a formatting error — it’s a real IP address sending mail that claims your domain without passing either check, and it’s exactly the kind of source a raw XML file would bury in a table of numeric attributes. In the dashboard it’s flagged plainly: unrecognized, failing, worth investigating before it’s worth ignoring.
The fix, not just the failure
A failing source on its own isn’t actionable — “SPF failed” tells you something’s wrong without telling you what to do about it. Norbelys pairs each finding with a concrete next step: which include mechanism is missing from your SPF record, which DKIM selector needs a key generated, or — for traffic you don’t recognize and can’t attribute to a legitimate service — whether it’s fine to let it keep failing while you climb toward a stricter policy. That last case matters as much as the fixable ones: not every finding needs an action, and the dashboard tells you which is which instead of leaving every row looking equally urgent.
The policy ladder, and where you are on it
DMARC’s policy field — p=none, p=quarantine, p=reject — decides what
receivers do with mail that fails authentication, and moving up that ladder
before your legitimate sources are clean is how domains accidentally block
their own real mail. The domain view shows the path explicitly: watch mode
first, where nothing is blocked and the goal is purely visibility; then
quarantine, once legitimate senders are staying aligned and failing mail is
worth treating as spam; then reject, once there’s been a stable stretch of
clean, aligned sending across every source you actually use. The decision
to move rungs stays evidence-based because the pass rate and the list of
still-failing sources are sitting right there when you make it, not
inferred from a gut feeling that “it’s probably fine by now.”
Month three: a quiet dashboard is the goal
The view on day one is naturally busy — every source is unverified until
it’s proven otherwise, and the first few reports are as much about
discovery as about compliance. A domain view worth aiming for a few months
in looks almost boring by comparison: a short, stable list of recognized
sources, compliance sitting close to 100% across all of them, and no
unidentified rows accumulating volume. That’s not the dashboard getting
less useful — it’s the dashboard reporting that the work is done. At that
point moving from p=none to p=quarantine, and eventually to p=reject,
stops being a leap of faith and becomes the obvious next step the pass-rate
history already supports.
A domain that never reaches that quiet state is telling you something too — usually that a legitimate sending source hasn’t authenticated correctly, or that spoofed traffic claiming your domain hasn’t stopped. Either way, that’s a finding worth acting on well before you’d consider tightening the policy further, and it’s exactly the kind of pattern that’s obvious across a few weeks of reports and easy to miss in any single day’s XML file.
Why this matters for a cold-email domain specifically
If you’re running outbound, DMARC isn’t a compliance checkbox — it’s part of what convinces Gmail and Outlook your domain is worth trusting at volume, the same reputation signal that warmup builds from the sending side. A domain with a published DMARC policy and a clean authentication record is a domain mailbox providers have less reason to second-guess. Skipping the monitoring step doesn’t mean your mail authenticates fine anyway — it means you find out it doesn’t from a bounce rate climbing for reasons you can’t see, instead of from a dashboard row that named the problem the day the first report showed it.
Included from the start
DMARC monitoring isn’t a Scale-tier add-on — it ships on every Norbelys plan from Starter up, the same way warmup and honest analytics do, because a domain’s authentication status isn’t something that should be gated behind a bigger invoice. If you’re already sending and haven’t looked at your DMARC posture, or you’re setting up a new domain and want the reporting address wired in before your first campaign, start on any plan and add the domain — the first report is usually a day away, not a project.