spf : the receiving server can check (in a public dns record) which server is allowed to send for this domain
dkim : the email is signed (using a private key) with a unique signature, the receiving server can validate the DKIM signature by running a DNS query to search for the public key for that domain .
dmarc : publish a policy on how emails that does not satisfy the above condition above (spf & dkim) should be handled (quarantine, reject) and optionally sends you a report on who send/tried to send emails on the behalf of your domain
Edit : I misread your question... it is odd indeed that only satisfying one condition is enough for a pass...