The following would be a simple but effective measure to reduce successful phishing attempts by 95% (I guess 😀) :
Do not allow a link to be opened from an email whose sender address is not stored in the address book or in a whitelist maintained by the user.
Actually, I think, this should be the the default behavior of Thunderbird that could be changed.
https://connect.mozilla.org/t5/ideas/thunderbird-phishing-assistance/idi-p/83080