I'm going to put the following in bold, so that every one who chances upon this thread sees it:
Assume by default that an email is a scam / spam.
Unless you are 100% sure the email is from who it says it is, then it's a scam. If it's from someone you know but it seems/looks odd then their PC might be infected. Just delete the email. If it's legit, they can always resend you the email.
If it's from a legitimate company, asking you to click a link and fill in details, then it's
always spam/scam. Banks will never send you emails like that. Nor will paypal, DHL, Fedex, any other shipping company.
I run a number of email servers and spam accounts for around 60% of our emails sent to us. It's thought that the real volumes could be around 80-90% of all email is spam/scam email.
On the subject of web security:
Always use a different password for each website.
A long password is better than a short password. eg:
dogs - poor
d0G$ - also poor
B4ndsaw$ - better, but not as good as you might hope
dogsbandsawsbobjanetomwillfredsueplanerouter - despite the number of dictionary words in it, actually pretty good (it's the length that's the important thing)
Or get a totally random one from here:
https://www.grc.com/passwords.htm
And use a password storage program to store your passwords.
And for online shopping if the price is too good to be true, then it's a scam. eg that camera that's £500 when everywhere else sells it for £1000, that's dodgy.