Phishing emails pretending to be PayPal are among the most common scams online, because almost everyone has a PayPal account and one convincing email can empty it. Attackers send fake "your account is limited", "unusual login detected", or "invoice sent" messages designed to steal your password, your money, or both. The signs below are the fastest way to tell a real message from a fake one.
Why these emails work
Fake PayPal emails succeed because they copy the real thing closely enough to trigger panic. The subject line mentions money, a login, or an account problem. The body uses PayPal's logo and tone. And the links point to a page that looks like the login screen — but is a lookalike domain controlled by the attacker. Slowing down for even a few seconds is usually enough to spot the fake.
1. Check the sender address, not just the name
The display name can say "PayPal" while the actual email address is [email protected]. Always expand the sender field and read the part after the @. PayPal's real messages come from paypal.com (like [email protected] or [email protected]).
2. Look at the link before you click
Hover over any button or link (on a phone, press and hold) and read the destination. A real PayPal link always starts with https://www.paypal.com/. Watch out for tricks like:
paypal-secure-login.xyz— looks related, but is not PayPal[email protected]— everything before@is ignored; the real destination isevil-site.xyzpaypal.com.secure-login.evil.com— the real domain is only the last part,evil.compaypal-support.comorpaypalsecure.com— close to the real name, but not owned by PayPal
If in doubt, do not click. Open a new tab, type paypal.com yourself, and log in there.
3. Urgency and threats
"Your account will be closed in 24 hours", "your funds are on hold", or "unusual activity detected" are designed to rush you. Real companies give you time, address you by name, and never threaten account closure over email to collect your credentials or card details.
4. Grammar and generic greetings
Phishing emails often start with "Dear customer", "Dear account holder", or "Hello member", and contain small grammar or spacing mistakes. PayPal addresses you by your name or business name in genuine messages.
5. Attachments
Real PayPal emails never send you a ZIP file, an invoice attachment, or a "receipt" that you did not request. Any attachment in a PayPal email is a red flag — treat it as malware and delete it.
Three checks before you click: sender, link, and urgency.
What to do if you already clicked or entered details
- Change your PayPal password from a device you trust, and make sure you are on paypal.com, not the phishing page.
- Turn on two-factor authentication so a stolen password is not enough on its own.
- Check recent activity for payments or changes you did not make, and report them to PayPal's resolution center.
- Report the email by forwarding it to [email protected], then delete it. You can also report to the FTC at reportfraud.ftc.gov and to IC3.
- If you entered card details, contact your bank or card issuer — they can block the card and reverse unauthorized charges.
Let Scam Guard check for you
Checking every email manually is tiring — and scammers keep improving. Scam Guard checks every site you visit against a list of known malicious domains and inspects links locally, so a fake PayPal page is blocked before you can enter anything.
Related reading: learn how to spot and avoid online scams in general, and how to spot fake bank text messages that use the same tricks on your phone.
Quick answers
What do I do with a suspicious PayPal email? Do not click, open, or reply. Forward it to [email protected], then delete it. PayPal uses those reports to take down the attack.
Can PayPal really call me or send texts? PayPal may call you for account verification in some cases, but it will never ask for your password, PIN, or full card number over the phone or by text. If you are unsure, call the number on paypal.com — never the number in the message.
Is it safe to log in through a link in a PayPal email? Only if the link really goes to paypal.com. The safest habit is to type paypal.com yourself instead of trusting any email link, even a real-looking one.
What if the email looks perfect? Attackers copy real templates. The sender address and the final domain in the link are the two things that are hardest to fake, so always check those two first.
Sources and further reading
- FTC: How to recognize and avoid phishing scams
- FTC: Report fraud online
- FBI IC3: Report internet crime
- PayPal: Official help and security center
Written by Hassan Arshad, founder of UsefulOrbit. Last updated August 31, 2026.