Anyone can send an email that claims to be from your domain. SPF and DMARC are how receiving mail servers tell the real messages from the forged ones — without them, or with DMARC left on p=none, a phishing email “from” your finance team to a customer arrives looking entirely legitimate. That is a direct route to invoice fraud and account takeover, and it damages trust in every genuine email you send.
CAA and DNSSEC protect the plumbing underneath your website. A CAA record limits which certificate authorities may issue certificates for your domain, which narrows the ways someone could obtain one they should not have. DNSSEC lets resolvers check that the answers they receive for your domain were not tampered with in transit. Neither is dramatic, but both appear on security questionnaires and in audits.
Missing DNS records are also easy to get wrong in the other direction. A DNS lookup that times out is not the same as a record that does not exist, and early versions of this check confused the two on our own domains. It now only reports absence from a definite answer, and shows you the exact query and response it saw.