It is almost nice to see I'm not alone in those, I've had some incredibly aggressive contacts from "security researchers" reporting about lack of SPF/DKIM records on personal, and throwaway, domains.
It's the same stuff that used to happen ten years ago regarding "clickjacking", and the lack of X-Frame-Options headers apparently meant the sky was falling, even though my SSL-protected site didn't host user-details, session-details, payment details, or anything other than static brochure content.