These multi-tenant mail sender orgs generally prohibit sending from domains that haven't been "verified". All of Microsoft 365 and Azure works this way. They don't let their customers spoof each other on shared infrastructure, you have to create TXT records in DNS zones to verify ownership.