@Edent "I can understand why .bid and .loan are popular with scammers. But why .mobi?!" -> because the avg user has 0 clue about what a domain name is, what its parts are and what they signify. Not to mention URLs...
"What can be done?" -> So far I could only think of enforcing a strict domain allow list for users (at the endpoint/browser) who don't know better.