Cloudflare's DMARC report intake rejects every aggregate report we send with "555 5.7.1 invalid_report_schema". Bisected against the live endpoint: the only element it objects to is <disposition>pass</disposition>, the value RFC 9990 added for mail that passed DMARC under an enforcing policy. The RFC 9990 namespace, <np>, <discovery_method>, <testing> and a missing <pct> are all accepted, and a report that differs only in using "none" there goes through. "none" (no action taken) is valid under both RFC 9990 and RFC 7489 and says the same thing to the reader, so reports now go out with it. The stored report keeps "pass"; only the serialized copy changes.