Here is a very common Facebook email requesting you to update your account settings. I get several each week.
They are not legitimate. There are 3 things to remember when you get emails asking you to login.
1. Legitimate emails will have your name in the greeting. Such as Dear Sally or Dear Margaret.
2. Hovering your mouse over where you have to click to sign should reveal the actual Facebook.com as the main domain, not the subdomain. Fraudulent emails will usually try to redirect you to a site that looks like Facebook but is a foreign domain instead like:
http://www.facebook.com.asditjiilil.com.pl
Facebook is there but not the main domain, instead a subdomain of the bad site asditjiilil.com.pl.
Just be observant when dealing with these emails.
3. Never click the unsubscribe button at the bottom.
Follow these rules and you should be fine.



