Good that you called out the lookalike gap, most DMARC guides skip it. The practical next step for a small business is watching for phishing domains that impersonate the brand: a lookalike with its own valid SPF/DKIM passes every check, so the only defense is spotting the domain itself.
Whoisfreaks' Threat Intelligence Feeds includes a daily phishing domain list (credential theft, fake logins, brand impersonation) that can be filtered for a brand name: whoisfreaks.com/products/threat-intelligence-feed