"And most importantly, the key trick is that you can put anything you want in the App Name field in Google"
Le sigh. That's where they put the email text. In the App Name field. Google can fix this by sanitising input better.
https://easydmarc.com/blog/google-spoofed-via-dkim-replay-attack-a-technical-breakdown/