It's not hard to spoof a legitimate email, all you have to do is copy the html that's usually found in an email, like a notification from Amazon, Citibank, etc. and then change the hyperlinks (URLs) to redirect to a scamming or phishing website.
When the email recipient opens the mail (assuming they view messages in HTML), it'll look legit.