I believe the failures in the "policy evaluated" section are what MxToolbox calls alignment failures. Which kinda makes sense, if a third party is signing email with a spoofed certificate but not actually sending from that certificate's domain. (If that's what misalignment means.) Here is their report on that XML: