I'm not sure I understand the issue. What are you doing with the emails received via webhook that SPF/DKIM is needed? Are they being imported into a CRM and re-displayed?
I treat any email message sent to the subdomain(s) configured for sending transactional / marketing messages as untrusted and act accordingly.