.xyz (alongside some others like .top, .biz?) in particular have a reputation for phishing/malware/etc., I think because they’re among the cheapest to register.
The funny thing is, the number 1 & 2 spam/phishing/malware domains that hit my company's mail server is gmail.com and outlook.com, followed by random .com domains.
My domain block list is approaching 1,000 domains and I don't think I have a single .xyz or .biz in there. There's a few .top. But the overwhelming majority is .com.