If auth passes and you're still in spam, stop looking at DNS
Most asked question I get, and the answer is almost never the DNS.
SPF, DKIM and DMARC prove the mail came from you and wasn't spoofed. That's the whole job. They get you past the forgery check at the door. They say nothing about whether Google actually wants to hear from you.
What decides placement is reputation and list quality, mostly. A domain registered six weeks ago has no sending history, and no history gets treated as guilty until it earns otherwise. There's no record you can add to skip that part.
The list is where I'd look first though. Scraped or old data carries dead addresses and traps, and one trap can take you from fine to poisoned inside a day. B2B data goes off fast because people change jobs constantly, so a list you verified three months ago isn't a verified list, it's a historical document.
Two specific things worth checking before you touch a DNS record.
Catch-all domains. Somewhere between a fifth and half of B2B domains accept mail to any address, so your verifier returns valid and it bounces anyway. If you're not running a separate catch-all check you genuinely don't know your bounce rate until you've already sent.
Per inbox volume. 30 to 50 a day is plenty for cold, and your warmup sends count toward that number. Most people forget the second half of that sentence and then wonder why a "slow" ramp isn't working.
And if you're running cold from your main company domain, stop today. Burn it and your invoices go to spam next to your outreach. Use domains you don't mind losing.