Collection
Deliverability & authentication
SPF, DKIM, DMARC, warmup and inbox placement
The unglamorous infrastructure that decides whether anyone reads your copy. Records, ramps, blocklists and the Gmail rules — explained without the XML degree.
67 resources in this collection
Start with these
Domain Health Checker
SPF, DKIM, DMARC and MX in one pass before you send a single email.
Read moreGmail & Outlook sender rules
SPF, DKIM, DMARC and the 0.3% complaint line — for busy people.
Read moreHow email warmup actually works
Pools, domain-safe cohorts, relationship memory, capacity gates and the limits of every inbox claim.
Read moreSPF Record Generator
Build a lean v=spf1 record with the DNS lookup budget counted live.
Read moreEverything else
"Delivered" doesn't mean anyone saw it. Here's the actual gap.
A 250 OK response only confirms a server accepted your message. Between that and a human actually reading it sit at least three more invisible steps.
Read more80% of phishing now uses AI content — so 'sounds AI-written' stopped being a tell
ENISA's Threat Landscape 2025 finds AI content in over 80% of observed phishing. What that means for detection, and why authentication is what's left standing.
Read moreA new standard could finally show you where your cold email actually lands
A proposed IETF spec called APRF would have mailbox providers report placement and engagement data back to senders, the way DMARC reports authentication failures.
Read moreA password manager just got impersonated by a domain one letter off
LastPass warned customers about phishing sent from lookalike domains it never owned — a reminder that DMARC doesn't stop a domain that merely resembles yours.
Read moreAI phishing jumped 14x in a month. Volume-based filtering can't keep up with that
Hoxhunt's 2026 data shows AI phishing going from 4% to 56% of reported attacks in a month, then settling near 40%. What breaks when growth outruns detection.
Read moreAll deliverability tools
26 free checkers, generators and calculators — no sign-up.
Read moreAlmost every bank has DMARC. Most still let spoofed email through
New 2026 reports show DMARC adoption is near-universal at banks, but only a minority enforce p=reject — the one setting that actually blocks spoofing.
Read moreAn unauthenticated Exchange spoofing bug shows why DMARC and patching aren't the same control
CVE-2026-42897, an exploited XSS bug in Exchange OWA, ran JavaScript from one crafted email — client trust and transport auth are different controls.
Read moreAOL Mail has a new owner. Here's what that means if you still send to it
Bending Spoons closed its acquisition of AOL from Yahoo in early 2026. AOL Mail still has tens of millions of users — here's what's known and unknown for senders.
Read moreBIMI explained: how a verified logo shows up next to your email
BIMI shows a verified logo next to your email in Gmail and Yahoo, but only after DMARC enforcement. What the record requires and what a VMC costs.
Read moreBlocklist Checker
Sweep your domain's IPs across 13 live DNSBLs with ASN context.
Read moreCheck this number before you check your reply rate
Reply rate tells you how last week's campaign performed. Domain health tells you whether next week's campaign will even reach the inbox. Here's what feeds it.
Read moreDKIM, explained: selectors, key sizes and the failures nobody notices
How DKIM signing actually works, what a selector is, why 1024-bit keys are on borrowed time, and how to check the key your domain is really using.
Read moreDMARC forensic reports (ruf): what they are, and why almost nobody sends them
The ruf tag asks for a copy of every failing message. What forensic reports contain, why most mailbox providers stopped sending them, and when to bother.
Read moreDMARC monitoring (product)
Aggregate reports turned into daily plain-language answers — included in every plan.
Read moreDMARC monitoring for agencies: one client's XML is manageable, twenty isn't
Running cold email or deliverability for many client domains means DMARC visibility across all of them at once. Why per-client XML doesn't scale.
Read moreDMARC Record Generator
Policy ladder, reporting addresses and every tag explained.
Read moreDMARC Report Viewer
Open RUA XML and read who sends as your domain — as a table.
Read moreDMARC setup for a new domain before you send your first cold email
SPF, then DKIM, then DMARC at p=none, then watch, then climb: the practical setup sequence for a new domain before its first cold email.
Read moreEmail blacklists: how to check if you're listed — and actually get off
Which DNS blocklists matter in 2026, how to check your domain and IPs in one sweep, and the delisting process that works (it's free, despite what some sites imply).
Read moreEmail Header Analyzer
SPF/DKIM/DMARC verdicts and every hop with per-server delay.
Read moreEmail warmup (product)
Unlimited mailboxes, included free — wired to your reputation guard.
Read moreEmail Warmup Calculator
Day-by-day ramp schedule for new mailboxes, with honest safety warnings.
Read moreEmail warmup week one: the ramp, the safety gates, and what the numbers do not prove
Norbelys starts at a base target of 5 and adds 2 per ramp day, though volume can be lower — why capacity, cohorts, and health matter more than a perfect chart.
Read moreGmail reject vs. quarantine: what you actually see when compliance fails in 2026
Non-compliant bulk mail to Gmail can hit permanent rejection, temporary throttling, or silent spam-foldering — three failures that look nothing alike in your logs.
Read moreGmail, Outlook and Yahoo don't police bulk senders the same way in 2026
All three require SPF, DKIM and DMARC — but the tools they give senders to see their own reputation, and what those tools actually show, are three different systems.
Read moreGmail's spam-complaint bar just got stricter: 0.1% is now the enforced number
Google Postmaster Tools' new verdict flags a spam rate above 0.1% as high — a number that used to be just a recommended target. What changed since our 0.3% piece.
Read moreHalf of your email opens are robots. Here's how to find the real number.
Apple Mail auto-opens every email, Gmail caches images, and security scanners click every link. What's left once you filter the noise — and how to decide on it.
Read moreHow a sending domain actually ends up on a blocklist
Not a single bad email. Blocklisting is almost always one of four repeatable triggers: trap hits, complaint-rate crossings, volume anomalies, or borrowed reputation.
Read moreHow long does domain warmup take?
Two weeks is a minimum observation period; new or high-volume domains can need four to eight.
Read moreHow many email addresses is the average professional actually juggling?
Worldwide, people carry 1.75 email accounts each on average in 2026 — and that ratio has been climbing for over a decade. Here's what's driving it.
Read moreHow much energy does sending one email actually use?
A single email costs a fraction of a gram of CO2 — until you multiply it by 361 billion sent per day. The real waste isn't email. It's mail nobody wanted.
Read moreHow to read a DMARC report (no XML degree required)
Gmail, Microsoft and Yahoo send you gzipped XML about every email claiming to be your domain. Here are the four fields that matter and how to spot a spoofer.
Read moreHow to read email headers like a postmaster
Received chains read bottom-to-top, Authentication-Results don't lie, and a five-minute header read explains most delivery mysteries. A field guide.
Read moreMicrosoft joined the bulk-sender rules in 2025 — and skipped straight to rejection
Google and Yahoo phased in bulk-sender enforcement gradually from 2024. Microsoft's 2025 rules skip straight to hard SMTP rejection — here's the real difference.
Read moreMTA-STS and TLS-RPT explained: the DMARC of the transport layer
DMARC protects who a message claims to be from. MTA-STS and TLS-RPT protect the connection it travels over — the two DNS records and policy file explained.
Read moreOne-click unsubscribe: the header Gmail and Yahoo now require
The List-Unsubscribe headers Gmail and Yahoo made mandatory for bulk senders, what actually satisfies the rule, and how enforcement tightened heading into 2026.
Read moreOver half a million domains are still at p=none. Is yours one of them?
The 2026 DMARC numbers show ~526,000 domains still parked at p=none. What that risks for the sender, not just the recipient, and how to leave it safely.
Read morep=none vs p=quarantine vs p=reject: when to move (and when not to)
More than half of domains with DMARC never leave p=none. Here's the honest ladder from monitoring to enforcement, with the checks to pass before each step.
Read moreReading DMARC XML reports by hand vs. having Norbelys do it
What manually parsing DMARC aggregate report XML files actually involves at real send volume, and why most teams stop doing it themselves within weeks.
Read moreRejection, soft bounce, or spam folder: reading a 2026 delivery failure correctly
Gmail, Yahoo, and Microsoft fail mail differently now — a hard rejection, a reputation soft bounce, and silent spam-foldering each need a different fix.
Read moreSecondary domains for cold email: never send cold from your main domain
The standard 2026 setup: lookalike secondary domains for outbound, 2-3 mailboxes each, round-robin under 40 sends a day, with the DNS records most guides skip.
Read moreSPF records, explained with real examples (and the 10-lookup trap)
What an SPF record actually says, how to read every mechanism, copy-paste examples for common stacks — and the DNS lookup limit that silently voids it.
Read moreThe 0.3% line: how spam complaints decide your sender reputation
Gmail and Yahoo enforce a hard 0.3% spam-complaint ceiling, 30 per 10,000 emails. The real math on how fast one bad send moves the needle, and how to stay under it.
Read moreThe 5,000-email threshold: how to tell if you're a 'bulk sender' to Gmail
Gmail's bulk-sender threshold counts messages to Gmail addresses only, not total sending volume — and the classification doesn't reverse once you cross 5,000/day.
Read moreThe blog
Full archive — deliverability, strategy and outreach craft.
Read moreThe pre-send cold email checklist: four gates, sixteen checks
Run every campaign through four gates before it sends: domain, list, copy, send settings. Sixteen checks, each with the free tool that verifies it.
Read moreWe tried warming up a mailbox by hand. Here's what that actually takes
The manual seed-account warmup routine, step by step, and where guessing a ramp schedule by hand breaks down compared to an automated warmup network.
Read moreWhat actually happens in the seconds after you hit send
Between your click and the recipient's inbox: a DNS lookup, a handshake with a stranger's server, and a filter deciding your fate — all in under two seconds.
Read moreWhat actually happens inside a spam filter before your email arrives
A spam filter isn't one gate reading your words and voting. It's three systems — identity, content and collective memory — scoring you in real time.
Read moreWhat actually happens the week you onboard a new client's domain
The real week-by-week workflow of bringing a new client's sending domain online at an agency — not the billing model, the actual DNS-to-first-send mechanics.
Read moreWhat changed in Google Postmaster Tools in 2026, and what to actually watch now
Postmaster Tools added a plain-language 'do users want your mail' verdict and a stricter spam-rate trigger. A guide to the new dashboard and what reputation means.
Read moreWhat warmup actually does for you before your first campaign even sends
Warmup isn't a feature you turn on later — it's what decides whether your first real campaign lands in the inbox or the spam folder. Here's what it does.
Read moreWhat you actually see when your DMARC report shows up in Norbelys
Not raw XML — a domain view with every sending source, pass rates, and a plain-language fix. Here's what the dashboard looks like on day one and month three.
Read moreWhich email client actually matters in 2026 (and why the answer is volatile)
Apple Mail and Gmail account for roughly 90% of tracked opens in 2026, per Litmus, but Apple's share swings 20 points month to month. What that means for testing.
Read moreWhy mailbox providers slow-walk mail from brand-new domains
A new domain and a spam operation's burner domain look identical on day one. That's the actual reason Gmail and Outlook cap what a new sender can send.
Read moreWhy plain-text emails still beat fancy HTML ones in cold outreach
A branded template signals 'campaign' to filters and humans alike. In cold outreach, the plainest-looking email is usually the one doing the least damage.
Read moreWhy sending from five mailboxes beats sending from one
One mailbox has a low daily ceiling no matter how much volume you want to send. Here's how spreading sends across several mailboxes actually protects deliverability.
Read moreWhy the same email looks different in Gmail, Outlook, and Apple Mail
Gmail, Outlook desktop, and Apple Mail don't share a rendering engine. One of them literally uses Microsoft Word — and that changes what you should design.
Read moreWhy your emails go to spam (it's rarely the words)
Spam placement in 2026 is mostly reputation, authentication and engagement — not trigger words. A diagnostic order that finds your real problem in 20 minutes.
Read moreYahoo added a one-tap unsubscribe button. It changes what your numbers mean
Yahoo's July 2026 update put unsubscribing one tap away, directly in the inbox. For senders, that reshapes what a rising unsubscribe rate actually signals.
Read moreYou set up bulk-sender compliance in 2024. Here's what's actually changed since.
SPF, DKIM, DMARC, and unsubscribe were the checklist in 2024. By mid-2026: Microsoft joined, Gmail's enforcement hardened, and the spam-rate target tightened.
Read moreYour email list rots before you send: clean it or pay in reputation
Why stale B2B lists turn into bounces, role inboxes, burners, and risky domains, how to clean a CSV before launch, and why Norbelys verifies every import.
Read moreReady to put this into practice?
Connect a mailbox and run the same checks on your own domain.