The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.
Just today I saw an e-mail from "onmicrosoft.com" that was completely legit.
I wonder how many domains MS is running these days. It seems like each department and project gets its own.
At least they're not sending from contoso.com ?
Every time I see a new Microsoft domain I've never seen before, I have to double check that it's actually legit. Every time I realize anew why people still fall for phishing attempts, because all these legit domains look like phishing attempts.
Note that XYZ.onmicrosoft.com is the domain you get when you sign up for hosted office 365 without a domain of your own