Revolut's fraudulent data request passed every email check. The government domain it came from was real
Revolut handed passports, verification selfies and full transaction histories for a limited number of customers to someone writing from a genuine government agency email domain. SPF, DKIM and DMARC all passed, correctly. Those checks confirm which domain sent a message. They say nothing about whether the sender has any right to ask.


