@deshipu @mntmn
you could but it's harder theses days.
The domain dhl.com which sens dhl express email have setup DMARC, SPF and DKIM. The first one advertises that all emails sent from that domain will have a cryptographic signature. Unless the phisher has access to that key, they can't sign their spoofed email. A decent email client would check the DNS record and know to check for the signature. Hiding the full email makes these protocols a lot less useful.