That's not even the only issue. What I was referring to is that anyone can pay a DNS registrar and have their very own domain name. And scammers create website with their own domain names very often, so the fact that they can isn't just hypothetical.
If someone creates a domain name and a NIP-05 identity with that domain name, clients will show a checkmark. Of course users can manually check that the domain name is a trusted one, but a checkmark conveys that the user is "verified", while the only thing that's been verified is that the owner of the account controls a domain name, which tells us nothing about trustworthiness.