> only interact with people using an official email address.
And then google whether the domain is associated with phishing attempts. i've been targeted several times recently by folks with "official" email addresses but whose domains are (per google) strongly associated with phishing.