List of top level domains: https://data.iana.org/TLD/tlds-alpha-by-domain.txt
The problem is that large companies and government agencies are both misusing and NOT using the appropriate trust anchor - their fucking domain.
Its just attempting to work around incompetence, which always just shows up again somewhere else.
The most recent one is detention-unit.com, which probably does trick a lot of the people getting these phishing emails since the targets don't seem to speak English as a first language.
As an aside, an alarming number of server admins don't check SPF so these emails are actually getting into people's inboxes.
I agree that this is the goal.
I wrote to their chatbot (of course, no human assistance) and after some time of "prompt engineering," or what one might call coercing, it finally directed me to a human consultant who confirmed it was indeed not a scam, and that it was indeed their messaging.
I opened the PDF, and it was pre-filled with someone else's data, with blank rectangles placed over fields in a bad attempt at redacting them (you could just move those rectangles around to reveal the underlying data).
The package later turned out to be a surprise from collaborators abroad. Years later, I still feel that scam aftertaste whenever I see the FedEx logo.
You should be more respectful, you’ve clearly received a Message direct from President Trump!
darth_avocado•44m ago