This setting enables the use of dmarc dns records to establish if DKIM signatures should exist for a particular domain, and what policy should be applied if the DKIM tests fails. This allows surgemail to safely enforce DKIM and reject more types of forgery/spam.
See https://surgemail.com/knowledge-base/sending-email-to-avoid-spam-filters-best-practices/