We are testing this here this afternoon so hopefully it will come good.
Interestingly I had just got onto this via a different method, because there is a message in one of the tenants that has reported this problem to us as follows:
Title: Reminder to authenticate outbound email with SPF, DKIM, and DMARC
User impact: If your organization hasn't already taken action, bulk messages sent with large BCC recipients may be rejected.
Current status: Based on customer feedback, we've refined our messaging to better reflect that we've learned of multiple email providers (Gmail, Yahoo, and others) rejecting bulk email sent from Microsoft 365 for some organizations, though not necessarily from your organization. This is a reminder that to increase deliverability of legitimate email to external recipients, it is important to authenticate your outbound emails. Information on how you can get started with email authentication in Microsoft 365 can be found in the corresponding link listed in the Additional diagnostics section of this message. Additionally, the non-delivery reports (NDRs) from these providers include details and best practices on how to deliver email to them. Please remember that Microsoft 365 is not to be used for bulk email relay, but in case the receiving email providers perceive your email as such, please read the limitations and guidelines for outbound spam protection listed in the Additional diagnostics section of this message.
It claims it will help those who are sending "a large rate or volume of email" - but in my testing it is genuinely only 2 or 3 on the CC or BCC line, or in our case via a distribution group, that has been triggering the NDRs.
So hopefully this will fix it. It's quite an escalation really, as Gmail only earlier this year finally required an SPF record... and all of a sudden they now seem to want DKIM and DMARC too.