Conversation

Ideally, you should add a NULL MX record alongside every A or AAAA record along with an SPF record. However, all that really matters is the top-level DMARC policy for the domain. SPF hardly does anything by itself. It's DMARC with a reject policy that prevents spoofing emails.
1
2
SPF can pass based on MAILFROM rather than FROM, i.e. someone can spoof an email from your domain but send it from a relay with valid SPF. SPF does not prevent spoofing. DKIM doesn't either since mail doesn't have to be signed. It's DMARC that makes this actually stop spoofing.
1
1