They've gotten pretty good at crafting domains this way.
I suspect it is quite easy to make it look like many people from an institution are in a thread and a passive participant is an email address from a 3rd party job portal.
*Might your own cultural expectations open you to attacks from a place with MIT's (recent if not current) network culture?
Edit: You added
> *Might your own cultural expectations open you to attacks from a place with MIT's (recent if not current) network culture?
after my reply. I’m not sure how it is relevant to your claim that “alumni are often allowed to keep their addresses”. In fact the question doesn’t make any sense to me; I’m not gonna accept an MIT job offer from an alum.mit.edu address (or more relevant to me, alumni.stanford.edu/alumni.princeton.edu), regardless of network culture.
Edit 2: Reread your question and realized you were implying that MIT "recently" allowed alumni to keep @mit.edu addresses. Well, you'll need to show some proof.
This approach to identifying phishing is ultimately insufficient.