20 years in this business, and I just broke 12 years of mailing list history because I got clever with DMARC.
Back when, p=none was good enough. Kids these days want p=reject and ARC and whatever else the RFC-of-the-month club dreamed up. Here's what actually happened, mark my words, someone else will repeat this mistake.
I moved a client to strict DMARC. Their alumni listserv, running on Mailman 2.1, forwards to Gmail and Outlook. Those forwards break SPF (new server IP). They break DKIM (Mailman adds footer). So they fail DMARC. With p=reject, Google bounces everything. Microsoft too. Twelve years of discussion archives, poof, silent failure for a week before anyone noticed.
The fix: ARC sealers. You need a server that validates existing ARC chains, then re-seals after modification. Mailman 3 supports this. Google checks ARC now. Microsoft started checking ARC last year. The spec lives at https://datatracker.ietf.org if you want to read it yourself.
But here's the pessimistic prediction: in three years, something else will break this. They always do.
My current working config for reference:
# /etc/postfix/main.cf - ARC setup
smtpd_milters = inet:localhost:8891
non_smtpd_milters = $smtpd_milters
milter_default_action = accept# opendkim.conf excerpt - sign AND verify
SignatureAlgorithm rsa-sha256
Mode svAnyone else solved this differently?