Taking a stroll through my spam folder, I saw a bunch of legitimate messages from people and companies with their own domains, that are not publishing DMARC and SPF records. Surely everyone (and by everyone I mean Google) is rejecting their mail? How do they not realize this?

Then I noticed that one of them was received *from* gmail, so their mail probably works fine so long as they only mail gmail users. But another was via Yahoo, so that doesn't track.
jwz.org/b/ykk8

0
0
0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/jwz/statuses/114213133217798587 on your instance and quote it. (Note that quoting is not supported in Mastodon.)