I have a simple policy.

If i receive any email requiring I login I never click a link. Instead I open a second browser and go direct.