The URL to which the target is redirected is typically a webpage crafted by the attacker to look like a genuine login page for the target’s email service
DO NOT enter your password after clicking on a link you got in an email, or an emailed pdf, or an emailed word document, or a link you got in telegram, or a strange url that came to you in a dream, or anything else like that. Why is it so difficult to get people to remember this?
I'm so old that I still remember when working in the fields picking fruit was a thing that local teenagers would occasionally do. And I'm not really that old, it was the 1980s. It's been quite a rapid change.