Phishing awareness is one thing.
When they check emails, they should always double check who is sending it. One common question I get asked - "Is this email legit?", where the email claims to be Microsoft, Google, etc. saying they _need_ to click this link to do X for their account.