It reads what is published. It cannot see what actually sends. An SPF record can be immaculately formed and still omit the marketing platform your team started using last quarter, which will not become apparent until the policy is enforced and those messages start failing.
It also cannot assess reputation. Authentication decides whether a message is trusted to be from you; reputation decides whether being from you is a good thing. A domain with perfect records and a history of complaints will still be filtered, and no DNS record will change that.
The genuinely useful version of this work starts with DMARC reports. Those reveal every source sending on the domain — including the ones nobody remembered — and turn a guess into an inventory. That is the point at which enforcement becomes safe rather than hopeful.