Just got an email from Medicare warning me of scams during Open Enrollment season. Naturally, the email has embedded URLs to click—and the links don't point to medicare.gov, they point to a .com that will forward the HTTPS request. (The email was also sent by that .com, but at least there's a valid DKIM signature.)