That is correct, since the primary idea behind the feature itself (SPF, DKIM, DMARC) is to ensure the incoming sender is verified for its authenticity. ESA presumes that outgoing emails from your domain is trusted and your internal on-prem or exchange online may never have such records published in general thats why its advised to be skipped.