the first lesson that i've been tought when it comes to suspicious emails is to double check the email it's been sent from. most companies will send an email most commonly from a (companyname).com/.org kind of email or .gov if it's a gov't agency. if it's something like (companyname) bunch of numbers (at) gmail.com then it's possible that it's a scam
most email providers usually send sus stuff to spam but if it's in your main inbox then double check that.
it's actually not that hard to replicate professional format emails from companies so long as you've got the usual wording down and the right images so that's why people are often encouraged to double check the sender