From a ESP (Email Service Provider) standpoint part of the issue is the recipients.
ESP wants to block all of auickbooks@notification.intuit.com because of all the phishing scams, but they can't. Users "need" (I disagree) it because they have multiple vendors who send out their invoices using that exact same address. So these phishing emails get through because someone "needs" their vendors (possibly intentionally) insecure server emailed invoice.
Come on people! Why aren't the vendors using their own email address. It can be configured in Quickbooks, it takes a bit work work and someone with at least a little bit of email server knowledge to get it set up. Why shouldn't we block vendors who are too lazy or too technologically challenged? If they are cutting corners, too lazy, or too tech challenged why should we even use their "regular" service in the first place?
I can say similar things about Google/gmail, Microsoft/outlook, Apple/icloud, and yahoo services. All it takes is a small bit of work and you have your own domain name to send from and not the providers, making it easier to add exceptions when needed, or better yet block when things go bad.
For a single domain, this is easy. For 20? 50? 1000+? not so easy.
It looks to be a poorly done job, until you find out that there are a users who want to see everything because they doesn't want to miss something important like their brother's cousinn-in-laws, child's pet's birthday picture from whomever may have taken it. These same users will complain if an email takes more than 20 seconds to get from Gmail/Outlook/Yahoo/etc to their mailbox. Now spread that over 1000+ domains on a mail server and you have a recipe to disaster that makes even the hardest working ISP's look bad.
I won't say all ISPs are good, or bad. Just remember that you see the output from the ESP that has to cover 1000's of different requirements vs the 1 set of requirement for your self run mail server..