I've taken your advice @Tigermann and sent an e-mail to c d o c c m @ m i c r o s o f t . c o m.
It contained a screenshot of the latest phishing example plus the internet headers details.
I also added a list of all the '.onmicrosoft.com' domains from which I've received similar phishing e-mails.
I've noticed that of the 94 domain names, nearly all appear to be company names! (For example,
'MercadoBentonTrading.onmicrosoft.com'.) I did a little research and they may well be names used by legitimate users but have somehow been hijacked by hackers.
This link, https://learn.microsoft.com/en-us/microsoft-365/admin/setup/add-or-replace-your-onmicrosoftcom-domain?view=o365-worldwide, explains for what these domains might be used. They appear to be what Microsoft term 'fallback domains' for Office 365 small business users. At any rate, it would appear that these socalled 'fallback domains' are vulnerable to hacking! You'd think Microsoft would be able to seal this breach!