In more detail
Typical signs are urgency, a link to a look-alike domain, an unexpected attachment and a mismatch between the displayed and real sender. Defences include checking the actual address, never signing in through an emailed link, Multi-factor authentication (MFA) (which limits what a stolen password gives) and DMARC on your own domain. A defanged URL, with dots and the scheme altered, is safe to share when reporting.