Adding the IP to SPF should be enough as long as you also meet that criteria:
Configure your setup only when you have fulfilled either of the following conditions:
- Sender domain: Ensure that the sender domain belongs to your organization (that is, you've registered your domain in Microsoft 365). For more information, see Add a domain to Microsoft 365.
- Certificate-based connector configuration: Ensure that your on-premises email server is configured to use a certificate to send email to Microsoft 365, and the Common-Name (CN) or Subject Alternate Name (SAN) in the certificate contains a domain name that you have registered in Microsoft 365, and you have created a certificate-based connector in Microsoft 365 that has that domain.