I think it's also worthwhile to mention DMARC: https://dmarc.org/overview/. Most of the major Email Service Providors (ESPs) support it.
SPF and DKIM signatures are two data points to help form an opinion about whether a message is legitimate. DMARC is your published policy about what to do with email that fails SPF and DKIM. If you have the strictest DMARC policy along with good SPF and DKIM records, and you're signing all your outgoing email correctly with DKIM, then this should solve your problem.
It's recommended to start with the most permissive DMARC settings (p=none) so you can make sure you don't prematurely block your own outgoing email.
I work for one of the larger (by market share) "send email via an API" services. This is a common issue we come across with our customers.