Inbound allow list bypassing all security checks?

We use MailChimp to send comms to our business and Sophos Email Gateway blocks messages from it with reasoning "Bulk".

Mailchimp uses our Domain name as an envelop, so we whitelist the address "" to allow messages to be delivered.

However if I understand it correctly adding sender in inbound allow list means it will skip all security checks (including SPF/DKIM/DMARC) which means this particular address "" can easily be spoofed now?

If that's right then is there a way to customize what checks to skip (Bulk in this case) and what to leave in place?