Jana, this is not the full message for the error email.
Yes, your understanding is correct, the problem lies with the sender's domain, and it’s their responsibility to fix it.
But because it doesn't include the complete error message, I cannot tell what is not fixed.
To prevent email spoofing, email providers like Microsoft use protections like SPF (to define which servers are allowed to send on your behalf), DKIM (to attach a digital signature to prove the email is real), and DMARC (to tell other servers what to do if a message fails these checks). If a spoofed email fails these checks, it will usually be flagged as spam or rejected. In the rejection email, it typically would say if SPF, DKIM or DMARC check passes or fails, but since the message isn't complete, I cannot tell which one failed.
As for others, without seeing the rejection email, I wouldn't be able to tell you the precise reason why it has been rejected.
Microsoft email users are targets of spam/scam and hackers. This is why Microsoft implements very strict email protocols like the requirement of SPF, DKIM and DMARC from other senders' domains.