I'm curious how the email attack worked, don't most web-based email services flag emails that come from one domain, but contain a link to another?
Yes, they should. I'd be curious to hear more details about that. I'd also like to know what domain was used for phishing, since you would think an infosec guy would either hover over the button/link before clicking, or get suspicious when he sees his browser load a site that isn't linkedin.com before redirecting.
Edit: Ignore it, I forgot he didn't control the DNS at that point. So this is invalid.