> Most people still trust display names over cryptographic identity.
People don't distinguish between domains with slight differences, and having little tools, and knowledge, to verify the related cryptographically identity, they tend to trust visual evidences.
The missing of NIP-05 verification in this context is just a silly error by the scammers, they could just add the NIP-05 using their damusish domains, and actually offer a more credible appearance.
In fact, NIP-05 verification usually doesn't mean *nothing*, and it's not a verification, if you don't know exactly the correct domain the user should be associated with.
The solution? Probably the simplest and most effective one is to display a WoT indicator near the profile, as
@npub13myx...v3qk cleverly does; the signal is clear: high number = trustworthy.