The visible sender can be misleading
In a spoofing attack, a message is designed to look as though it came from a familiar company or domain. The aim is usually to increase the chance that the recipient trusts a link, attachment or payment instruction.
SPF, DKIM and DMARC help mail providers evaluate whether a sender is authorised. They cannot eliminate every form of phishing, but they make direct abuse of a properly protected domain significantly more difficult.