SPF, DKIM, and DMARC
SPF (RFC 7208) publishes which hosts may send mail for a domain. DKIM (RFC 6376) signs a message and publishes the public key in DNS. DMARC (RFC 7489) states what to do when the visible From domain is not aligned with a passing SPF or DKIM result, and where to send reports.
SPF checks the envelope domain during SMTP. DKIM verifies a cryptographic signature in the message header. DMARC needs at least one of SPF or DKIM to pass in alignment with the From header domain before it treats authentication as successful for policy.
Where each record lives
SPF is a TXT record at the domain name used in the MAIL FROM or HELO/EHLO identity during the SPF check. DKIM stores a TXT record at selector._domainkey.domain where selector and domain come from the signature. DMARC is a TXT record at _dmarc.domain.
A receiver can show SPF pass and DKIM pass in the Authentication-Results header while DMARC still fails, because alignment compares organizational domains or exact hostnames according to the published aspf and adkim tags.