There have been cases recently of exploits that successfully spoof valid DKIM credentials too:
https://easydmarc.com/blog/google-spoofed-via-dkim-replay-at...