SPF is enough to prevent spoofed source of SMTP envelope, but not for From: spoofing. (applying it to From: address would reject any forwarded mail, which probably isn't desired)
DKIM ensures legitimacy of From: address, and works correctly with forwarding. But DKIM itself doesn't specify whether you should require DKIM signature. (ADSP record allows to specify that, but it wasn't deployed nearly at all)
DMARC record is used to specify unambiguous policy, and it passes when either SPF is aligned with From: address, or there's valid DKIM signature. Thus DKIM+DMARC is enough to prevent spoofed mail, but SPF is usually kept in case some servers still don't support newer methods. SPF+DMARC would also prevent spoofing, but will also reject forwarded mail.
Note that SPF+DKIM without DMARC doesn't really protect against spoofing, because SPF checks only envelope address, and you cannot tell whether DKIM signature is required.
dkim : the email is signed (using a private key) with a unique signature, the receiving server can validate the DKIM signature by running a DNS query to search for the public key for that domain .
dmarc : publish a policy on how emails that does not satisfy the above condition above (spf & dkim) should be handled (quarantine, reject) and optionally sends you a report on who send/tried to send emails on the behalf of your domain
Edit : I misread your question... it is odd indeed that only satisfying one condition is enough for a pass...
But this is from the RFC document, so it may be that in practical cases things are more nuanced.
A message satisfies the DMARC checks if at least one of the supported authentication mechanisms:
1. produces a "pass" result
Personally I did not test yet what a DMARC result 1 fully failing check produces.
I can say however that only 1 successful identifier-alignment criteria (and the other credential being valid but not aligned) is enough for an overall pass.Of course the receiving mailserver is free to enforce a strict DKIM&SPF requirement aside the DMARC check/spec. If your question is why that would be necessary, I'd love to hear the reason aswell
Based on the RFC, for the rest of possible SPF configurations (more strict), SPF record would be enough. But I am guessing based on the RFC document and my experience.