SPF and DKIM can be applied just fine to subdomains, I don't understand the suggestions made for email, yet there are good reasons to have a few extra domains, none which are actually mentioned: accidental cookie leakage and redundancy being obvious ones. The implication made for the API domain was that it should not be protected by SPF and DKIM
I stopped reading there