Very sad that legitimate emails are often so bad that even after researching for 10-15 minutes I cannot be sure if a message is legitimate or not. And I'm working with email professionally (as sysadmin/SRE) for more than 10 years.
Regular email users who are not email expects can either trust all emails or delete most of them. Security trainings which tell don't open suspicious emails are useless because most emails are suspicious. PayPal, many utility providers even some big banks send very suspicious emails.
A typical example of fishy but legitimate emails is when company with the main domain example.com send emails from a different but similarly looking domain e. g. example-invoices.com and: whois is hidden using whois privacy, there is no website on this domain (even if there is - why should I trust it?), infrastructure is completely different from the main domain. In other words example-invoices.com have nothing in common with example.com the only way I can think example-invoices.com is legit - they know some personal data of a recipient but if you're paranoid you can expect this to come from a breach which nowadays are common.