Authenticated Received Chain (ARC) is an email authentication system designed to allow an intermediate mail server like a mailing list or forwarding service to sign an email's original authentication results. This allows a receiving service to validate an email when the email's SPF and DKIM records are rendered invalid by an intermediate server's processing.

How an ARC signed message ensure that the AR headers are legit?

I'm trying to wrap my head around the ARC policy and from my understanding, an email arriving with an ARC headers means that the previous Authentication-Results headers have been validated by the sender. Or, from Wikipedia: Authenticated Received…
