@cybertrapped
Safest approach is reaching out via a second communication channel (say telephone them using a phone number you found independent of the one in email signature) to verify.
If this is not an option, verifying the SPF record and DKIM signature should provide a reasonable indicator that the email was sent by someone controlling the domain, as well as (assuming they don't have an unauthorized 3rd party using their mailserver).
Hope this was helpful. :)
You will not believe it unless you are experiencing it, but whether I make calls through smart phone, or VoIP, I seem to always be talking to impersonators. I have not been able to disconnect Internet service despite talking to Cox customer rep (whom now I recognize was an impersonator) who assured the service would be disconnected.
This is why I am trying to figure out how to evaluate the emails.
I shared the phone call at the bottom of this post: https://cybertrapped.substack.com/p/update-getting-help-for-declined
I went to the Milpitas Citibank, and I was allowed to make a call from their office phones. The passphrase was not enough to identify myself; I could give him the last 6 numbers of my checking account