Using something like GPG email signing is not something I can ask our accounting or marketing team to reliably and securely do on their own (especially when everyone is working remotely).
LearnDMARC [1] was posted here recently and can show you how this is validated.
DMARC and friends can help verify the sender was authorized to use the address if setup in the right ways, but that doesn't mean that the address it was sent from is the person the recipient expected.
Especially in today's email clients that don't show the sender address a lot of the time.