It should be a big red flag for sure, but the reality is most users aren't going to understand that. They got told to use a password manager by someone or find it convenient, but they don't understand the security flow enough to catch that it's a potential attack, or how to resolve it safely.

Historically I've seen lots of sites do a subdomain shuffle for login pages every now and then which routinely breaks domain matching, introducing false positives that users have to deal with, making them numb to the threat too. Passkeys baking in the domain check with no workaround means that sites can't do that, which is a benefit.

My password manager's browser integration breaks on every update of Firefox, which seems like it is a weekly affair. I got rid of the extension, and copy/paste everything.

Password managers were never meant to solve the problem of phishing, and aren't really capable of that. They solved the problem of password reuse. They do that just fine.