Install Electrum from the official source http://electrum.org  & Verify signatures

Ask people you trust & check multiple hard to forge online sources e.g. first slide of presentation at a bitcoin conference on official YouTube channel & http://electrum.org  & Devs twitter
Example of an electrum phishing popup.
This is how you verify the signature:

https://electrum.readthedocs.io/en/latest/gpg-check.html

The key thing is to verify the key
(6694 D8DE 7BE8 EE56 31BE D950 2BD5 824B 7F94 70E6) truly does belong to Thomas Voegtlin.

As mentioned, there are many ways to do this and you should use more than one to be sure
For example at 3:22:30 in this conference Thomas V shows his key which you can see matches

Here is a good thread by @_benkaufman that explains how this phishing actually works https://twitter.com/_benkaufman/status/1299971319430352897?s=20
You can follow @6102bitcoin.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled: