"Note that the bitly link was not directly visible in the phishing email, as it was an HTML-email. That is another lesson learned: Back to standard, text-based email as the default."
Thunderbird has phishing/scam detection built in that shows a pop-up with "this message might be a scam" if there is URL-like text in the message that points to another, different URL. So having the text "www.google.com" with a link to bit.ly would show a warning.
Sadly it is a bit overzealous and shows messages with say www.google.com that go to www.google.com/ as malicious too (i.e. trailing / so the text and URL don't exactly match though they resolve to the same thing), but the idea seems sound. I'm surprised gmail doesn't have something like this.
I always look at the mouse over url. And check the URL in the address bar. And rely on the password manager in the browser. And sometimes login in a new tab, then go back and reload the link.
bit.ly addresses don't keep their URL in the address bar (Eg. http://bit.ly/19y8wyr for HN), so it's possible you might not notice it once you've clicked, depending on how realistic the malicious target URL was.
Password managers really help in that situation. They will refuse to autofill your Google password if you're redirected to a domain that looks like google.com but actually contains weird Unicode characters, for example.