Replying to @trojanfoxtrot@infosec.exchange
Honestly, too many. And half of them are just to answer one thing: is that link or sender a real service the attacker is hiding behind, or actually shady?
Phishing leans on trusted names (SendGrid, a Google Doc, Cloudflare). Sorting the legit hops from the bad one eats most of the time.