I can't believe he omitted that detail. How did they appear to send an email from a google domain? This is especially puzzling given that he says he works in security.
minimal efforts, won't pass any scrutinity but someone panicking might miss it.
Thanks OP for the thread, very enlightening.
I wonder how many people would fall for that though.
The headers uploaded are the report email being sent to Google, not the original incoming email. We still don't know how this was spoofed.