When your server sends a message, the receiving server has to decide within milliseconds whether it is genuinely from you. It has no relationship with you and no way to ask. What it has is a set of public records your domain publishes, and it forms its judgement almost entirely from those.
Three records matter. SPF states which servers may send on your behalf. DKIM provides a cryptographic signature proving a message was not altered. DMARC ties the two together and tells receiving servers what to do when a message fails.
Incomplete configurations rarely fail loudly. Messages are delivered, mostly, and the ones diverted to spam produce no notification. The cost accumulates quietly as quotes that were never read and notifications that never arrived.