You have whitelisted a sender's Email ID in the client net portal under Anti-spam > Approved senders in order to bypass DMARC validation, but the sender is still rejected.
Email Security.cloud
Having a primary domain added under approved senders while not selecting the bypass of the spoofing will result in any email ID under that domain to not bypass the whitelist.
If Spoofing option bypass is selected for an email ID , while the spoofing whitelist for the primary domain was not selected, the bypass will not work.
A few steps to check in order to whitelist a sender :
1 - Ensure that the sender is not whitelisted per email ID while the primary domain has not been whitelisted to bypass Spoofing.
Example of a domain not whitelisted :
2 - The whitelisted domain should not be wildcarded
3 - The Email ID should not be wildcarded