We recommend a phased approach to securing your email:
Choose an anti-spoofing management tool
Protect email in transit
Configure anti-spoofing controls
Send spoof emails to spam
Spoof emails being rejected
Continuous improvement
The size and complexity of your organisation, the amount of change occurring and resources available to you will determine exactly how long you need.
Once you have secured your emails in transit, and implemented a DMARC policy of 'reject' on all of your domains, you should regularly conduct health checks and fix any problems which show up.
You should create a basic plan for your implementation.