Conversation

No one said DKIM is required. To prevent spoofing email from a domain to properly configured servers, only a DMARC p=reject policy is required. That requires that there is either valid, aligned DKIM or valid, aligned SPF. Lack of a DKIM / SPF setup will result in rejection.
1
If you want to extend the topic to actually sending email that passes DMARC, then sure, you can implement that with either SPF or DKIM instead of both. That's how DMARC works. However, if you only do SPF, you won't be able to send email via mailing lists / relays like with DKIM.
2
DKIM + DMARC is a lot more flexible because mails can be forwarded as usual, and it remains valid as long as there's no tampering with the email. A mailing list can still prepend List-Unsubscribe and other headers that aren't oversigned. DMARC with SPF only works directly.
2
1
DMARC verification will pass with DMARC and DKIM set up properly. A DMARC policy with p=reject is fully compatible with mailing lists as long as they don't tamper with emails. Mailing list software should leave emails alone. They shouldn't tamper with signed headers / content.
2
1