diff --git a/.cursor/rules/panel-ui-system.mdc b/.cursor/rules/panel-ui-system.mdc
index 06b8a32..8bd512f 100644
--- a/.cursor/rules/panel-ui-system.mdc
+++ b/.cursor/rules/panel-ui-system.mdc
@@ -12,7 +12,7 @@ Do not copy `internal/web/view/templates` into mockups. Do not mark `` as
Compose screens from `stack`, `pair`, `measure`, `fill`, `field-row`, `actions-row`:
- Two peer jobs → `pair` (one child shrinks to `measure`).
-- Tables/logs/DNS → `fill` (nowrap + overflow-x on the card).
+- Tables/logs/DNS → `fill` (nowrap + overflow-x on the card). Add-to-list is a `measure` row inside that card, not a second card above it.
- Confirm/login/user form → `measure`.
- Host ‖ Type and two equal inputs → `field-row` (shared grid row, not two `.code` paddings).
- Save + Delete → `actions-row` inside the card; never submit inside ``.
diff --git a/CHANGELOG.md b/CHANGELOG.md
index 38d7ac5..c8f112d 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -29,6 +29,11 @@ Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); version
Regions are `stack` / `pair` / `measure` / `fill`; Host ‖ Type is
`field-row`; Save + Delete is `actions-row`. Shared chrome is `shell.js`.
+- docs: panel UI mockups — add-domain sits in the list card (Domains and
+ Inbound); DMARC candidate screens drill into a domain roll-up and a
+ parsed aggregate report (aligned vs third-party fail), not a hub-only
+ summary.
+
## [1.3.0] - 2026-08-14
Security and quality after 1.2.5: domain-admin send-log authorization,
diff --git a/docs/assets/panel-ui/app.html b/docs/assets/panel-ui/app.html
index e9c5195..23cb394 100644
--- a/docs/assets/panel-ui/app.html
+++ b/docs/assets/panel-ui/app.html
@@ -28,6 +28,9 @@
"inbound-backup": "inbound-backup.html",
"inbound-delete": "inbound-delete.html",
dmarc: "dmarc.html",
+ "dmarc-domain": "dmarc-domain.html",
+ "dmarc-report": "dmarc-report.html",
+ "dmarc-report-fail": "dmarc-report-fail.html",
help: "help.html"
};
var h = location.hash.replace(/^#/, "");
diff --git a/docs/assets/panel-ui/dmarc-domain.html b/docs/assets/panel-ui/dmarc-domain.html
new file mode 100644
index 0000000..2c41e09
--- /dev/null
+++ b/docs/assets/panel-ui/dmarc-domain.html
@@ -0,0 +1,88 @@
+
+
+
+
+
+example.com — DMARC — SelfPost mockups
+
+
+
+
+
+
+
Backup-MX / forwarder. Accepts on port 25 only for listed domains. Recipients are either an allow-list or any address at that domain. Off by default in Compose.
stack: overall → pair очередь‖TLS → pair milters‖PTR → inbound если есть → pair machine‖processes → configuration. На карточках остаются числа и Detail.
hub: pair ingest ‖ this week, затем fill список отчётов. Домен: roll-up (pair 7 days ‖ third-party, fill reports + sources). Один XML: просмотр — pair report ‖ policy, fill records. Не дашборд, не ruf=.