Using prepared statements, with the PDO database driver it would be something like this
$stmt = $pdo->prepare('INSERT INTO user (email) VALUES(?)');
$stmt->execute([$email]);
For a full example you can look here, includes injection example