Phishing emails pretending to be PayPal are one of the most common scams online. Attackers send fake "your account is limited" or "unusual login detected" emails designed to steal your password and money.
Here are the exact signs to check before you click anything.
1. Check the sender address, not just the name
The display name can say "PayPal" while the actual email address is [email protected]. Always expand the sender field and read the part after the @.
2. Look at the link before you click
Hover over any button or link. A real PayPal link always starts with https://www.paypal.com/. Watch out for tricks like:
paypal-secure-login.xyz— looks related, but is not PayPal[email protected]— everything before@is ignored, the real destination isevil-site.xyzpaypal.com.secure-login.evil.com— the real domain is only the last part
3. Urgency and threats
"Your account will be closed in 24 hours" is a classic pressure tactic. Real companies give you time and never threaten account closure over email to collect credentials.
4. Grammar and generic greetings
Phishing emails often start with "Dear customer" or "Dear account holder" and contain small grammar mistakes.
5. Attachments
Real PayPal emails never send you a ZIP file or invoice attachment that you did not request.
Let Scam Guard check for you
Checking every email manually is tiring — and scammers keep improving. Scam Guard checks every site you visit against a trusted list of known malicious domains and inspects links locally, so a fake PayPal page is blocked before you can enter anything.