Since February 2024, Gmail has required anyone sending more than 5,000 messages a day to personal Gmail accounts to authenticate with SPF, DKIM and DMARC. Yahoo set similar requirements. Outlook.com followed in May 2025 for senders over 5,000 a day.
And the minimum DMARC policy they accept? p=none.
Which is why "we meet the bulk sender requirements" and "we're protected from spoofing" are completely different sentences.
p=none with a reporting address: you get reports about spoofing.
p=quarantine / p=reject: you tell receivers to quarantine or reject mail that fails.
The requirements got a lot of senders to publish DMARC. Getting to enforcement is the part that actually protects your domain, and it's still where most orgs stall.