First, you need to know that spammers/scammers and con artists are simply moving their practices to the digital age.
Second, you can trust absolutely nothing that you have no control over. If I drop a letter in your mailbox, it may be completely forged, both the header and the contents. Without encrypted emails, non-repudiated and mutual authentication, email is simply a crap shoot these days.
Third, I can completely forge my own IP, in real time, and appear that I'm sending emails from Germany, West Madagascar Province or Newark, NJ. Don't matter - it's all possible. And real. And easy.
best option? Call them up via voice. Humans are great Turing detectors.
