That is how it suppose to be, to avoid malware, by visiting just official websites. But we should also remember there are other things to do to avoid malware, especially by avoiding ads and torrent files.
Unfortunately, there are so many traps from scammers and newbies are easily and naively to be caught by scammers. Even not newbies still can be caught if they are careless at some points.
It is like in cryptocurrency, I learned an important thing. Don't trust, verify and double check. Even you receive email that looks to be legit, you must go to an exchange and double check for latest announcements, news from their official site. If there is nothing relates to the email you receive, be careful it can be punny code, homograph attacks.
DMs from strangers, simply ignore, block and report them as scammers.