Pick your email providers and generate the exact TXT records you need to paste into your DNS.
Check the services that send mail on behalf of your domain. Each one adds a DNS lookup to the SPF budget.
TXT record for the root domain
v=spf1 ~allRoll out DMARC in stages: start at "none" with a reports email (rua) for a few weeks to see what would get rejected, and only then move to "quarantine" and finally "reject". Publishing "reject" from day one can make you stop receiving your own mail if something isn't configured right.
Without a reports email, "none" is pointless — nobody sees what would be failing.
TXT record for _dmarc.tudominio.com
v=DMARC1; p=none;The DKIM record isn't generated here: your email provider (Google Workspace, Microsoft 365, SendGrid...) issues it, because it has to match the private key it signs your mail with. A record invented on this page wouldn't be signed by anyone and would be useless. Copy the TXT record your provider gives you and add it to your DNS alongside these two.
SPF and DMARC are just email. Certificate, headers, ports: check it all for free in a minute with the full analyzer.