I would sincerely hope .gov addresses use SPF/DKIM/DMARC. That makes spoofing impossible. In Revolut's case, the sender's email system had been compromised.