This is actually worse than that. The emails are correctly signed by PayPal - DKIM, DMARC and SPF are correct. Which points to one of few possibilities. 1, Paypal mail servers were hacked and used to send this out 2, Paypal DNS management has been hacked and the records were updated to cover the IP the mail is sent out of 3, Paypals Mail security suite has been hacked Either way, this is pretty bad as the email headers look like they have come from Paypal directly. M.
... View more