Might not be as common now but years ago there used to be websites when you bought something the payment page to put in your card details etc was http:, should aways be https: (the s stands for secure). Most payment pages are https but there 'might' be some old skool ones still as a standard page of http which isnt good news at all.
But emails with logon links from banks, you know the phising emails, banks will never send you an email asking you to login, they may send you an email saying 'please check your account' but you then login yourself not via an email.
If you get a phising email, hover over the link and it'll often have some crazy russian link instead of
www.hsbc.com
If you are in a cybercafe or using a computer at a school/college always log out of a site properly, clicking X in the corner to close the browser wont necessarily log you out.
Saying that common sense helps, the amount of times i have friends stupidly forwarding emails saying 'is this legit' when its soooo clear its not (saying that people often reply to 1 post scammers here with 'welcome to the forum' despite the scammers initial post having links at the bottom for louis vuitton etc ! Duhhhh !