This came to my mind too. But by using a password manager it will be able to differentiate between the GOOD and BAD site. So I think the point is valid only if the user is not using a password manager.
Here's a blog on how to verify a domain for sending in SES until they update their docs. It describes the process with Namecheap as DNS provider but is transferable to most providers.