Skip to content
← BlogDeliverability6 min read

What you actually see when your DMARC report shows up in Norbelys

Not raw XML — a domain view with every sending source, pass rates, and a plain-language fix. Here's what the dashboard looks like on day one and month three.

By David Lara, Founder

Founder-reviewed ·How we research and correct articles

Somewhere between adding a DMARC record and actually understanding your domain’s authentication status sits a folder full of gzipped XML files that almost nobody opens. Gmail, Outlook and Yahoo all send them daily once you’re set up to receive reports — and almost none of that data is human readable without processing it first. This isn’t another explainer on what DMARC does or how to read the raw reports by hand — those exist and cover the protocol well. This is what shows up on your screen once Norbelys is doing that processing for you.

Day one: waiting, then collecting

After you add the domain and merge Norbelys’s reporting address into your DMARC record’s rua field, the domain view starts in a waiting state — there’s nothing to show yet because no receiver has sent a report. That usually changes within a day, sometimes faster: the first aggregate digest arrives from whichever mailbox provider processes your mail soonest, and the status flips from waiting to collecting. From that point the view fills in gradually as more providers report, typically settling into a complete picture across a full reporting cycle rather than all at once.

Getting reports flowing in the first place

The setup itself is a DNS change, not a product configuration screen full of settings to get right:

From adding a domain to a readable view

  1. Add the domain

    Enter the sending domain in the workspace. Norbelys generates a reporting address scoped to that domain.

  2. Publish or merge the rua record

    Add the provided address to your DMARC TXT record's rua field — merge it in alongside any existing reporting address rather than replacing it, if you already have one.

  3. Reports start arriving

    Aggregate XML begins landing from participating mailbox providers, usually within a day of the record propagating.

  4. Read and act from the domain view

    Sources, pass rate, alignment and named findings are already parsed and waiting — no XML to open by hand.

What the domain view actually shows

Once reports are flowing, the page you land on isn’t a report — it’s a running answer to “who is sending mail as my domain, and is it landing clean.” Every source that’s touched your domain in the reporting window shows up as its own row, whether that’s your own outbound infrastructure, a known transactional service, or something you’ve never heard of:

SourceVolumeSPFDKIMCompliance
Google Workspace9,824100%99.9%99.9%
SendGrid (known service)2,907100%98.1%98.4%
185.17.4.21 (unidentified)1150%0%0%

The unidentified row is the one worth stopping on. That’s not a formatting error — it’s a real IP address sending mail that claims your domain without passing either check, and it’s exactly the kind of source a raw XML file would bury in a table of numeric attributes. In the dashboard it’s flagged plainly: unrecognized, failing, worth investigating before it’s worth ignoring.

The fix, not just the failure

A failing source on its own isn’t actionable — “SPF failed” tells you something’s wrong without telling you what to do about it. Norbelys pairs each finding with a concrete next step: which include mechanism is missing from your SPF record, which DKIM selector needs a key generated, or — for traffic you don’t recognize and can’t attribute to a legitimate service — whether it’s fine to let it keep failing while you climb toward a stricter policy. That last case matters as much as the fixable ones: not every finding needs an action, and the dashboard tells you which is which instead of leaving every row looking equally urgent.

The policy ladder, and where you are on it

DMARC’s policy field — p=none, p=quarantine, p=reject — decides what receivers do with mail that fails authentication, and moving up that ladder before your legitimate sources are clean is how domains accidentally block their own real mail. The domain view shows the path explicitly: watch mode first, where nothing is blocked and the goal is purely visibility; then quarantine, once legitimate senders are staying aligned and failing mail is worth treating as spam; then reject, once there’s been a stable stretch of clean, aligned sending across every source you actually use. The decision to move rungs stays evidence-based because the pass rate and the list of still-failing sources are sitting right there when you make it, not inferred from a gut feeling that “it’s probably fine by now.”

Month three: a quiet dashboard is the goal

The view on day one is naturally busy — every source is unverified until it’s proven otherwise, and the first few reports are as much about discovery as about compliance. A domain view worth aiming for a few months in looks almost boring by comparison: a short, stable list of recognized sources, compliance sitting close to 100% across all of them, and no unidentified rows accumulating volume. That’s not the dashboard getting less useful — it’s the dashboard reporting that the work is done. At that point moving from p=none to p=quarantine, and eventually to p=reject, stops being a leap of faith and becomes the obvious next step the pass-rate history already supports.

A domain that never reaches that quiet state is telling you something too — usually that a legitimate sending source hasn’t authenticated correctly, or that spoofed traffic claiming your domain hasn’t stopped. Either way, that’s a finding worth acting on well before you’d consider tightening the policy further, and it’s exactly the kind of pattern that’s obvious across a few weeks of reports and easy to miss in any single day’s XML file.

Why this matters for a cold-email domain specifically

If you’re running outbound, DMARC isn’t a compliance checkbox — it’s part of what convinces Gmail and Outlook your domain is worth trusting at volume, the same reputation signal that warmup builds from the sending side. A domain with a published DMARC policy and a clean authentication record is a domain mailbox providers have less reason to second-guess. Skipping the monitoring step doesn’t mean your mail authenticates fine anyway — it means you find out it doesn’t from a bounce rate climbing for reasons you can’t see, instead of from a dashboard row that named the problem the day the first report showed it.

Included from the start

DMARC monitoring isn’t a Scale-tier add-on — it ships on every Norbelys plan from Starter up, the same way warmup and honest analytics do, because a domain’s authentication status isn’t something that should be gated behind a bigger invoice. If you’re already sending and haven’t looked at your DMARC posture, or you’re setting up a new domain and want the reporting address wired in before your first campaign, start on any plan and add the domain — the first report is usually a day away, not a project.