I swear, the proliferation of random ".xyz" type gTLD is not making things any easier in stopping non tech people from clicking on phishing links. There's so damn many of them. Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose...
List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt
My theory is that it devalues the domain name thus increasing the value of search sites.
BTW, it'd be nice if browsers automatically show the CNs of the "Issued-To:" and the "Issued-By" in the security certificate.
The menagerie of TLDs is somewhat a necessary evil in my view. Prior to them it was becoming nearly impossible to get a decent domain, with most of them already having been laid claim to by squatters, big companies, and startups with VC money to burn.
I definitely don't trust those when they show up in search results, and even when they sometimes appear here in articles voted to the front page, I tend to ignore them.
Sure, if they didn't exist people would use phishing domains like "fedex-secure-delivery-approval.com" or something, I suppose
Many-legit-sounding-hyphenated-words-domain is actually another red flag for me, as that was indeed what they did before the proliferation of TLDs.
This was a calculated project by ICANN to 1. bring lots more money to ICANN and 2. prevent decentralisation of the DNS root away from the control of the USA.
Not helped by legitimate websites often redirecting you through weird multi tiered domains especially during log in, or legitimate businesses using link shorteners instead of their full domains, or more and more businesses themselves hopping on new TLDs, like the recent cloudflare wallet release.
For the past 2 years I've gotten backscatter from a phishing campaign that uses a domain I own in the from address. Every single domain they try to get the victims to click on is a .com
The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language.
As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes.
I'm not convinced that would help.
The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.
Its just attempting to work around incompetence, which always just shows up again somewhere else.