Now that TLS certificates are nearly ubiquitous, they no longer serve as any sort of signal about the legitimacy of domains. I'm thinking that checking the whois database to determine the recency of a domain's registration may be useful to signal at least that caution is recommended.

Similarly, if possible (with all the 'privacy' options available to domain registrants, it may not be possible), letting people know the country the registrant is in may be helpful as well.

