I control if the address look legit. And if it is supposed to be an email from some company, then i go directly to their website where I have account and check it right there, so I am sure and don’t click any phishing links. If it was phishing, then tag as spam and delete it
How often do you update your passwords for online accounts?
I update my passwords after a security breach or after i decide to do it