In the case of spoof/phishing sites, having the base domain be shown as it is in Canary might actually be helpful - instead of a long complicated URL that allows the scammer to camouflage their fake domain, the domain will be explicitly called out.

I don't hate this change so far (especially as clicking on the domain gives the full URL - although that's perhaps not very discoverable if you don't know about it already)

