Best way to avoid FB phishing: don't have a FB account.
If that's not an option, it is imperative that you use a unique email address for communication from FB which you do not share with anyone else, human or corporate. https://infosec.exchange/@happygeek/113787777146227848