When you forward an email, unless the email forwarder modifies the message content, it should still match the DKIM signature, so it still passes.
Because as you say, you break SPF if you don't touch the envelope from. There's SRS to fix this. But if you do that, you break DMARC alignment.
So... something is always broken? It appears to me there's no way to make mail forwarding that works with full SPF/DKIM/DMARC setups.
"In April 2024, Google will start rejecting a percentage of non-compliant email traffic and gradually increase the rejection rate. For example, if 75% of a sender’s traffic meets our requirements, Google will start rejecting a percentage of the remaining 25% of traffic that isn’t compliant."
Untrusted forwarders (also sometimes known as open relays) have been heavily frowned upon for a really long time. SPF has never worked for forwarders that don't do rewriting. Those letters have always been negatively looked upon, unauthenticated mail is a remnant of times long gone.
Google's policies about authentication are the bare minimum you should be doing anyways if you care even a little bit about your customers or recipients in general.