Is everything OK based on this DMARC report?
Those are DMARC record attributes. The report means you didn't specified any policy, and remote servers will apply a default behaviour for mail which is not properly signed.
See https://dmarc.org/overview/ :
pct Percentage of messages subjected to filtering
p Policy for organizational domain
sp Policy for subdomains of the OD
adkim Alignment mode for DKIM
aspf Alignment mode for SPF
If you want remote parties to to reject non-signed mail that has your domain in the envelope from, specify p=reject
. For the same with subdomains of your original domain, if they don't have their own records, sp is used as a policy. In this case, pct
is a percent of messages to reject.
Note, remote server doesn't have to follow your guidelines. They may not reject if they won't. They even may don't check a signature at all. You can't do anything about it. In reality this shows your confidentiality in that you are configured everything and you are sure any your mail must be signed.
The signature itself is generated correctly. Nothing prevents remote parties from up-scoring your signed mail and down-scoring the mail which has your domain in envelope from, but was not signed, even in the absence of published policy.