Failing SPF doesn’t matter if a DMARC policy is in place. You just need to pass SPF or DKIM at that point. It’s why it’s important to setup both.
Both fill in gaps in the use case of the other.
Both fill in gaps in the use case of the other.
DKIM completely supersedes SPF, hence my recommendation to just skip SPF.
Additionally, DKIM keys need to be rotated periodically just like SSL. Many services like Sendgrid or ProtonMail will handle this for you now by setting up multiple CNAME records so they can rotate the keys for you, but it only works with that sender.
SPF helps to address the gaps. I totally agree that strict DMARC policy plus DKIM should be enough though.