DNSBL are good to have
in addition to checking SPF+DKIM+DMARC. This is because spammers now mass produce domains with valid SPF+DKIM+DMARC using Cloudflare and GoDaddy for domain registration, WHOIS and DNS because neither company gives the slightest care about abuse (and actively go out of their way to make reporting abuse arduous), and the source IPs could be anywhere in the world.
One thing that does work to combat these SPF+DKIM+DMARC valid sources, I've found, is to reject all email from supposed email servers which either don't have working reverse DNS or which have reverse DNS which has a name that differs from the HELO / EHLO name.
It used to be enough to just insist on working reverse DNS that has matching forward DNS resolution, but recently I've been testing requiring that "Return-Path" has the same domain as the HELO / EHLO.
Another thing that I've noticed but I'm not sure how to check in sendmail is to reject email that has a "Return-Path", "From", "To", or "Reply-To" that's a Gmail address when the email isn't from Gmail. I'd like the same test with Outlook / Hotmail and Yahoo. I've found almost no instances of legitimate email sent this way.
Many things to consider, now that SORBS is one less tool to use!