

Even if they could reuse a DKIM hash on an email (pretty sure this is unique per email and would fail on a legitimate check), SPF would show its obviously not from Google. So just make sure your email server correctly handles DKIM verification and blocks SPF hard fails, and you’re probably good against this.
Looks like it’s because it’s labeled as a Higher-Speed Rail rather than High-speed.