DMARC ties it together
DMARC says: a message must pass SPF or DKIM and align with your domain. It then applies your policy and emails you reports.
Ramp the policy safely
Start at p=none (monitor only), review reports, fix legitimate senders, then move to p=quarantine, and finally p=reject to block spoofing outright.
Alignment is the catch
Passing SPF/DKIM isn't enough — the domains must align with your From address. Misalignment is the usual reason mail still fails DMARC.
Mail can pass SPF and DKIM and still fail DMARC if neither aligns with your From domain.