Same Story as it ever was. The first time I encountered what I thought was a phishing attack at the bank I worked at 25 years ago, it turned out to be a marketing campaign, with URLs that put our company name as a user before the domain name (back in the day when creds could go in the URL).
It's probably easier for the marketing department to get a new domain up and running that it is for a new subdomain within their own company. Battling Business Units and all that.
You really would think that at least in theory a company like Cloudflare would make it very easy for internal teams to automatically request new subdomains
Running marketing off a separate domain is often a conscious decision because if they start getting blocked for spam, then critical service/operational emails from your actual domain might also get blocked.
Oh good, I'm glad that Cloudflare, proud defender of internet security, is properly focused on the important goal of optimizing for their ability to send promotional emails to my inbox rather than silly things like helping prevent phishing attacks.