One thing I use as a clue is the email address. I kinda figure that a legit offer would't use Yahoo or Netscape or Hotmail, etc. as a return address -- a legit business can most probably afford a REAL email address.
And then there is the WHOIS lookup. I did one of these on a "bank problem" email found that the IP was registered to an address in an industrial park in Cairo, Egypt.