Check the sender's address
The senders email address may look trustworthy at first, but the name after the ‘@’ (the domain) can give you a clue as to whether it's bogus. For example if the email is sent from: @eonHelpDeskUK.com, this is likely a phishing attempt, as we’d only send emails from @eonenergy.com.