@dalias @riastradh This historically allowed arbitrary impersonation of your domain because SPF is ignored if DMARC is enabled and DKIM is valid. You could encrypt it with a key that's mostly zero bits though.
I wrote up my tooling for publishing keys: