Below is a set of DNS records for a made-up domain that is having trouble with spoofed mail.
There is exactly one reason mail claiming to be from this domain still passes basic checks when sent from an unrelated server. Find the record that is wrong, and submit the mechanism that makes it permissive as the flag, for example skrd{+all}.
Read the SPF record carefully. The last token is the whole answer.