> using evidence of technical competence achieves nothing
Evidence of technical competence wasn't what I was talking about. I meant that it creates a trail of evidence for police to actually pursue them, particularly in the case of phishing.
To setup DMARC, DKIM and SPF you need to control a domain. Somebody has to own that domain, unless you just hacked a DNS or somebody's already configured email server.
If you hacked it, there's a trail to contact the domain owner to notify them. If you bought it, there's a trail to find the domain owner.
You can obfuscate that with stolen cards and fake registration details, but now there's a central point where identity validation and security can concentrate itself.
A lot of positive side effects happen when the bar is raised from "any email server can send email claiming to be from anybody" to "email can only be sent claiming to be from a domain if the domain approves the sending email server."
At least when the spam concentrates from major senders like Google, etc those major senders have the means to analyze and take steps to prevent it.