The summary.
REJECT AT THE TRANSACTION RATHER THAN ACCEPTING AND BOUNCING
Accepting then bouncing sends mail to forged senders and makes you a source of backscatter.
The envelope and the headers can differ, and the authentication mechanisms check different ones — that distinction underpins everything.
ONE COMPROMISED ACCOUNT DESTROYS EVERY CUSTOMER'S DELIVERABILITY
Per-account limits with automatic suspension are essential, because the damage happens in minutes and manual response is too slow.
Require that the authenticated user owns the sender address.
PUBLISH A POLICY IN MONITORING MODE FIRST, AND READ THE REPORTS
They reveal legitimate systems sending as your domain that you had forgotten. Publishing a rejecting policy first silently destroys real mail.
REMOVE ADDRESSES IMMEDIATELY ON PERMANENT FAILURE
Continuing to send to invalid addresses is a strong negative signal.
Separate transactional mail from marketing, so complaints do not block password resets.
FALSE POSITIVES COST FAR MORE THAN FALSE NEGATIVES
A missed spam message is an annoyance; a rejected invoice is a business problem. Quarantine rather than delete, and give users visibility.