2 answers
The most important thing is to check the sender's email address carefully, because it often doesn't actually match who they claim to be - like you see "paypa1.com" instead of "paypal.com" or weird domains. Then look out if they're asking for personal info or passwords in an urgent way, with an alarmist or threatening tone, because legit companies never do that via email. Another red flag is when links look normal but clicking them takes you to a different website (hover your mouse over it to see the real URL). If you're in doubt, don't click anything and contact the company directly through their official number or verified website.
Never click on links in emails that arrive out of the blue, even if they look official. Like, if you get a message from your bank saying "verify your account right now," don't go straight through the link in the email. Open your browser, type the website address yourself, and log in from there. Phishers are counting on us being in a hurry or distracted.
Beyond what people have already said about checking the email address (which is really crucial), pay attention to the language and visual details too. If the email is poorly written, with grammar or spelling mistakes, that's already a red flag. It happens to me a lot when I'm driving for work that I get emails from insurance companies or clients, and I can tell right away when something's off. A real official communication is usually more polished. Even a crappy logo, colors that have nothing to do with the official brand, weird fonts... all that's enough to make me suspicious.
Another thing that's saved me several times: if you're not sure, contact the company directly using a phone number from their official website or from a paper document you got before. Don't reply to the email and don't use the contacts you might find linked in the suspicious message. Take five extra minutes, but at least you'll sleep soundly.
Your answer
Log into answer.