> virtually all the spam coming in had valid SPF / DKIM / DMARC, as do most of the phishing attacks.
This should create a means to go after the domain owners via registrar and trail of ownership, even so far as blocking email from the domain.
Forcing the spammers to pass DMARC creates a burden and an evidence trail that didn't exist before.
They're generally hosted on a google or microsoft 365 or something slightly less shady. Good luck with that.