I already get all sorts of emails sent to the address listed on whois. Most, if not all, are outright scams. So now one of those will actually be genuine?
Basically the same way you tell if any email you receive is genuine and not a phishing attempt.
Also, consider using your registrar's WHOIS privacy service, if they provide one: your registrar only has to ensure the details you provided are genuine, and those can be masked in WHOIS.
But which one?