Evil-doers are using a Zendesk email domains to phish. My catch-all email address got a wave of emails overnight "from" organizations who have not implemented SPF, DKIM, and DMARC.
Shame on:
alltrails.zendesk .com
arc .net
bang-olufsen.zendesk .com
community .com
findingfocus.zendesk .com
fivebelow.zendesk .com
gamerhash.zendesk .com
migrationwiz .com
nowgg.zendesk .com
resilio .com
revenue1.zendesk .com
thehunter.zendesk .com
webtoon .com