Back to Learning CenterSecurity

Paypal phishing scam email

By Samuel ChenardAugust 11, 20267 min read
Paypal phishing scam email

A PayPal phishing scam email is a message that impersonates PayPal to pressure you to click a link, call a listed number, open an attachment, share information, or pay. Do not use the message to verify its claim. Open PayPal independently in your browser or app instead. If there is an unfamiliar invoice or money request in your account, do not pay it and use PayPal's reporting guidance for that request.

At a glance

Quick takeaways

  • Do not click links, call phone numbers, or download attachments in a suspected PayPal impostor message.
  • Open PayPal independently rather than through the email's buttons or instructions.
  • An email that claims a payment occurred and an unfamiliar in-account invoice are separate situations.
  • An unfamiliar invoice or money request is not a reason to pay or contact the number shown in the request.
  • In U.S. PayPal guidance, suspected impersonation emails can be forwarded to phishing@paypal.com.
  • A message that passes SPF or DKIM is not, by itself, proof that the payment claim or request is honest.

How a PayPal phishing scam email works

A PayPal-branded phishing message often tries to create urgency around a payment, account limitation, refund, security alert, or invoice. The attacker wants the recipient to act through a channel they control, such as a link, attachment, or phone number in the message.

PayPal's guidance for reporting suspicious messages says not to click links, call phone numbers, or download attachments in messages from PayPal imposters. That advice matters because a convincing logo, sender display name, or payment-related wording does not establish who controls the destination behind a link or number.

The safe decision starts outside the message. Type the PayPal address into your browser yourself, or open the PayPal app directly. Then compare the message's claim with activity visible in your account. This is a PayPal-specific application of the broader checks in Palisade's phishing email example guide.

Decision flow for a suspicious PayPal email, separating an unmatched email claim from an unexpected PayPal invoice or money request
Source: Palisade.

When the answer changes

The key distinction is whether you are looking at a suspicious email claim or an actual unfamiliar invoice or money request visible after you opened PayPal independently.

If you cannot find matching activity in PayPal, treat the email as a suspected impersonation message. Do not reply to it, use its links, or call its phone number. Use PayPal's suspicious-message reporting guidance instead.

If you do find an unfamiliar invoice or money request in PayPal, do not assume that its presence makes it legitimate. PayPal's invoice and money request scam guidance says to verify through the PayPal website or app, not pay an unfamiliar request, and not use phone numbers or links in the request.

Neither branch is a private fraud determination. A message can make a false claim about an activity that does not exist, while a real request can still be unwanted or suspicious. The decision rule is about choosing a safe verification and reporting path before you disclose information or send money.

For the wider threat category, see Palisade's email security learning hub and threats and impersonation guidance.

A worked PayPal phishing decision rule

Use this decision rule when an email says that a PayPal payment, invoice, refund, account restriction, or security event needs your attention.

  • On receiving a suspicious PayPal-branded email: do not click, call, reply, or download an attachment.
  • Verify independently: open PayPal through the app or a typed address, never the email's link.
  • If no matching activity appears in PayPal: report the suspected email through PayPal's applicable guidance.
  • If an unexpected invoice or money request appears in PayPal: do not pay it; report the request through PayPal.
Do not publish, forward, or paste private account information, payment details, passwords, one-time codes, or full email headers into an untrusted channel while checking the message.

A sender display name such as "PayPal" can be chosen by an attacker. The visible text of a link can also differ from its actual destination. Those clues can justify caution, but they do not replace independent verification in PayPal.

Email authentication has a similar boundary. SPF and DKIM help receivers evaluate whether a message was authorized to use certain sending identities, but they do not prove that every message's business claim is genuine. Why phishing emails can pass SPF and DKIM explains why authentication results must be interpreted within their limits.

What to do with the evidence you have

If you only have the email, leave its links, attachments, and phone numbers unused. Open PayPal independently and look for the transaction or account activity the message claims exists.

If no matching activity appears, report the suspected email. PayPal's U.S. suspicious-message guidance directs users to forward suspicious emails to phishing@paypal.com. That address is stated in U.S. guidance, so do not assume it applies in every country or region. Use PayPal's local security or help resources when your account is outside that scope.

If you find an unfamiliar invoice or money request after opening PayPal independently, do not pay it. PayPal's instructions for cancelling or reporting a suspicious invoice or money request document the reporting route through the PayPal website or app.

Do not contact a phone number supplied in an unfamiliar invoice or money request. Use PayPal independently to find support and reporting options.

If you already clicked a link, entered credentials, shared a code, downloaded an attachment, or sent money, the pre-click decision is no longer enough. Follow the recovery-focused actions in what to do after clicking a phishing link.

Evidence

Sources and further reading

Questions readers ask

Frequently asked questions

See which senders are using your domain

Start in Palisade.

Get started

Share this article

Samuel Chenard

Written by

Samuel Chenard

CEO & Co-Founder, Palisade

Samuel Chenard is the CEO and co-founder of Palisade, AI-first DMARC software for IT teams and MSPs, from one domain to thousands.

More from Samuel

Related articles