# "Important Update To PayPal Communications"

**URL:** <https://boards.straightdope.com/t/important-update-to-paypal-communications/581656>\
**Category:** Factual Questions\
**Created:** [May 12, 2011, 3:20pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656 "2011-05-12T15:20:59Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Quasimodem](https://avatars.discourse-cdn.com/v4/letter/q/e274bd/32.png) [@Quasimodem](https://boards.straightdope.com/u/Quasimodem)\
**Post date:** [May 12, 2011, 3:20pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/1 "2011-05-12T15:20:59Z")

</div>

I just received this e-mail in address I rarely use. Does anyone know if this is legitimate?

When I went to the address mentioned in the mail and logged in, I got the green writing on my address bar and the verisign lock, but I know that fishing is very sophisticated these days, so I thought I’d ask here.

I did log in, but I immediately had second thoughts and went to paypal (the address I have) and changed my password.

Anyone else receive this?

Thanks

Q

---

<div class="post-metadata">

**Author:** ![smithsb](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/smithsb/32/12107_2.png) [@smithsb](https://boards.straightdope.com/u/smithsb)\
**Post date:** [May 12, 2011, 3:24pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/2 "2011-05-12T15:24:38Z")

</div>

Yeah, it’s spam/phishing/etc…  
You did the right thing going to the real site and changing your password.

Never go to the site in the email. (My, they do look authentic though).

Use your known address.

---

<div class="post-metadata">

**Author:** ![GuanoLad](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/guanolad/32/42_2.png) [@GuanoLad](https://boards.straightdope.com/u/GuanoLad)\
**Post date:** [May 12, 2011, 3:26pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/3 "2011-05-12T15:26:26Z")

</div>

Paypal’s legitimate emails will greet you by name. The phishing emails don’t, and will call you “Paypal User”.

Not sure why, but so far that has been consistent for me.

---

<div class="post-metadata">

**Author:** ![Quasimodem](https://avatars.discourse-cdn.com/v4/letter/q/e274bd/32.png) [@Quasimodem](https://boards.straightdope.com/u/Quasimodem)\
**Post date:** [May 12, 2011, 3:47pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/4 "2011-05-12T15:47:58Z")

</div>

> [@GuanoLad](#):
>
> Paypal’s legitimate emails will greet you by name. The phishing emails don’t, and will call you “Paypal User”.
> 
> Not sure why, but so far that has been consistent for me.

It did call me “Bill Craig”… so I am hoping I am okay. Thanks VERY much!

Q

---

<div class="post-metadata">

**Author:** ![control-z](https://avatars.discourse-cdn.com/v4/letter/c/eada6e/32.png) [@control-z](https://boards.straightdope.com/u/control-z)\
**Post date:** [May 12, 2011, 3:48pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/5 "2011-05-12T15:48:31Z")

</div>

They sent me one I think is legit that said this:

> [@](#):
>
> Please provide your consent to our Electronic Communications Delivery Policy so that we can continue providing you with your account information electronically. Agree Today
> 
> KEEP GETTING YOUR ACCOUNT INFO ELECTRONICALLY Log in & agree to our Electronic Communications Delivery Policy
> 
> Hello (my real name),  
> PayPal is updating the way we send you your account information. We’d like to continue providing you with your account information electronically, including transaction receipts, account statements, and annual disclosures.  
> Please agree to our Electronic Communications Delivery Policy today. It’s easy to do and only takes a few clicks:  
> Log in to PayPal  
> Click the Electronic Communications Delivery Policy link and read the policy  
> Click the checkbox to accept the policy  
> Click Agree and Continue  
> That’s it!  
> Electronic delivery is fast, convenient, and secure. Please log in and accept our Electronic Communications Delivery Policy today. If you’ve already done so, please disregard this e-mail.  
> Agree today
> 
> Your acceptance of our Electronic Communications Delivery Policy does not change (or override) any previous request to opt out of marketing communications.  
> © 2011 PayPal Inc. All rights reserved. PayPal is located at 2211 N. First St., San Jose, CA 95131.

My question is, what are they asking me exactly? I didn’t do anything because how else are they going to communicate with me? Are they going to be required to snail mail people since they’re acting like a bank?

---

<div class="post-metadata">

**Author:** ![Quasimodem](https://avatars.discourse-cdn.com/v4/letter/q/e274bd/32.png) [@Quasimodem](https://boards.straightdope.com/u/Quasimodem)\
**Post date:** [May 12, 2011, 3:51pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/6 "2011-05-12T15:51:55Z")

</div>

Also, I have to ask why didn’t they also send this to the e-mail address I use for paypal purchases. The other address I used specifically for the bicycle ride I did for the animals last year.

Weird.

Q

---

<div class="post-metadata">

**Author:** ![Dewey\_Finn](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dewey_finn/32/4222_2.png) [@Dewey\_Finn](https://boards.straightdope.com/u/Dewey_Finn)\
**Post date:** [May 12, 2011, 3:52pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/7 "2011-05-12T15:52:03Z")

</div>

If you get one of those emails, don’t click on the link in the message. Instead go to the Paypal (or eBay or bank website) yourself using the URL already in your bookmarks. A lot of times, the address displayed in those emails looks OK, but goes to a different site.

---

<div class="post-metadata">

**Author:** ![Annie-Xmas](https://avatars.discourse-cdn.com/v4/letter/a/ecc23a/32.png) [@Annie-Xmas](https://boards.straightdope.com/u/Annie-Xmas)\
**Post date:** [May 12, 2011, 3:58pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/8 "2011-05-12T15:58:29Z")

</div>

I always mouse over and look at the address. If it isn’t “paypal” I delete it.

---

<div class="post-metadata">

**Author:** ![control-z](https://avatars.discourse-cdn.com/v4/letter/c/eada6e/32.png) [@control-z](https://boards.straightdope.com/u/control-z)\
**Post date:** [May 12, 2011, 4:01pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/9 "2011-05-12T16:01:33Z")

</div>

> [@Quasimodem](#):
>
> Also, I have to ask why didn’t they also send this to the e-mail address I use for paypal purchases. The other address I used specifically for the bicycle ride I did for the animals last year.
> 
> Weird.
> 
> Q

What probably happened is someone had your bicycle address in their address book and they got hacked.

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [May 12, 2011, 6:26pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/10 "2011-05-12T18:26:51Z")

</div>

> [@Annie-Xmas](#):
>
> I always mouse over and look at the address. If it isn’t “paypal” I delete it.

This isn’t safe in general, because people can use [unicode characters that look a lot like normal english letters](http://en.wikipedia.org/wiki/IDN_homograph_attack) to lead you to another site.

Sometimes they can also exploit bugs in web browsers to display a different address.

Basically, anything coming in via email is not to be trusted.

---

<div class="post-metadata">

**Author:** ![cochrane](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cochrane/32/10441_2.png) [@cochrane](https://boards.straightdope.com/u/cochrane)\
**Post date:** [May 12, 2011, 7:22pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/11 "2011-05-12T19:22:05Z")

</div>

If you haven’t deleted the email, forward it to [spoof@paypal.com](mailto:spoof@paypal.com) so that their fraud team can track it down. They are very proactive about online security and they’ll appreciate the tip.

---

<div class="post-metadata">

**Author:** ![Quasimodem](https://avatars.discourse-cdn.com/v4/letter/q/e274bd/32.png) [@Quasimodem](https://boards.straightdope.com/u/Quasimodem)\
**Post date:** [May 12, 2011, 7:34pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/12 "2011-05-12T19:34:10Z")

</div>

Done. Thanks **cochrane**. Let’s see what the reply is. I will post it here.

Thanks

Q

---

<div class="post-metadata">

**Author:** ![gotpasswords](https://avatars.discourse-cdn.com/v4/letter/g/c57346/32.png) [@gotpasswords](https://boards.straightdope.com/u/gotpasswords)\
**Post date:** [May 12, 2011, 8:34pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/13 "2011-05-12T20:34:07Z")

</div>

I have not received an email about their Electronic Communication Delivery Policy, but I just now went to PayPal by typing “paypal” into the browser on a Mac that does not receive my PayPal emails and I got a page to approve the policy. Looks like they specifically need your approval to email IRS Form 1099-K, rather than snail-mailing it.

Digging deeper online, it looks like only PayPal users who receive over $20,000 per year _and_ have over 200 sales per year will get a 1099-K, so unless you’re running a thriving home business on eBay, you probably won’t have to worry about the tax form. They’re just making sure all users know about the policy. Considering how many millions of users they have, it makes sense that they’re sending out the emails in batches.

---

<div class="post-metadata">

**Author:** ![Jackmannii](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jackmannii/32/311_2.png) [@Jackmannii](https://boards.straightdope.com/u/Jackmannii)\
**Post date:** [May 12, 2011, 8:55pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/14 "2011-05-12T20:55:19Z")

</div>

I got an ingenious e-mail a couple days ago purporting to be from PayPal, saying in part:

\*Notification of Limited Account Access

Dear Jackmannii,  
As part of our security measures, we regularly screen activity in the PayPal system. We recently contacted you\*\* after noticing an issue on your account.We requested information from you for the following reason:

We recently received a report of unauthorized credit card use associated with this account. As a precaution, we have limited access to your PayPal account in order to protect against future unauthorized transactions.

Case ID Number: PP-XXX-XX-XXX

In accordance with PayPal’s User Agreement, your account access will remain limited until the issue has been resolved. Unfortunately, if access to your account remains limited for an extended period of time, it may result in further limitations or eventual account closure. We encourage you to follow our verification procedure as soon as possible to help avoid this.

Click here to login and restore your account access

Once you log in, you will be provided with steps to restore your account access. We appreciate your understanding as we work to ensure account safety.\*

The right-hand column of the e-mail message urged me to be wary of scammers and to only go to real PayPal addresses (the sample given looked real enough). However, they also provided a link, and the e-mail came from a sender ending with …paypall.com (two letter ls).

So I took a wild guess that this was a scam and reported it to PayPal, who has not yet responded.

Gosh, maybe there _is_ a problem with my account. :eek::dubious:

> [@GuanoLad](#):
>
> Paypal’s legitimate emails will greet you by name. The phishing emails don’t

The above e-mail _did_ use my name. I still think it’s a scam.

\*\*actually this was the first contact. I suspect our scammer, though possessing reasonably good grammar skills, has a problem with past/present tense.

---

<div class="post-metadata">

**Author:** ![CC](https://avatars.discourse-cdn.com/v4/letter/c/f1d935/32.png) [@CC](https://boards.straightdope.com/u/CC)\
**Post date:** [May 12, 2011, 8:56pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/15 "2011-05-12T20:56:50Z")

</div>

I get an e-mail from Paypal about once every three days or so. I have never even opened them. They always warn me about some pending deadline and I’ve always been suspicious. I seldom have used Paypal, but when I have, I have not had any problems, so I’m convinced that the e-mails I receive are fraudulent. I did forward one or two to Paypal but never heard back. (Or, if I did, I ignored it, figuring it was spam.)

---

<div class="post-metadata">

**Author:** ![H3Knuckles](https://avatars.discourse-cdn.com/v4/letter/h/ba8739/32.png) [@H3Knuckles](https://boards.straightdope.com/u/H3Knuckles)\
**Post date:** [May 12, 2011, 10:06pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/16 "2011-05-12T22:06:49Z")

</div>

By the way, I read that some of the phishing scams now use a mock-up of the real site that passes your log-in forward to the real deal and takes you to the actual logged in landing page now, so that it’s much harder to tell if you’ve been scammed.

Once again, the best answer is to always manually navigate to the site using a known url rather than taking e-mail links.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [May 12, 2011, 10:33pm UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/17 "2011-05-12T22:33:27Z")

</div>

Paypal actually did send an e-mail about a change to their policy in the past week or so. My wife asked me about one, and I logged directly onto Paypal. Sure enough, there was a new agreement that required you click “I agree.”

If you’re in doubt, go to the website directly. Type [www.paypal.com](http://www.paypal.com) in your browser (and make sure it’s spelled correctly). As a further check, make sure the page takes you to your Paypal account (a phish would give an error or something that has none of your personal information).

---

<div class="post-metadata">

**Author:** ![Askance](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/askance/32/8281_2.png) [@Askance](https://boards.straightdope.com/u/Askance)\
**Post date:** [May 13, 2011, 1:38am UTC](https://boards.straightdope.com/t/important-update-to-paypal-communications/581656/18 "2011-05-13T01:38:21Z")

</div>

> [@Annie-Xmas](#):
>
> I always mouse over and look at the address. If it isn’t “paypal” I delete it.

> [@iamthewalrus\_3](#):
>
> This isn’t safe in general, because people can use [unicode characters that look a lot like normal english letters](http://en.wikipedia.org/wiki/IDN_homograph_attack) to lead you to another site.

This. And the scammers can use URLs with the string ‘paypal’ in them, like [heldesk-paypal.user-support.com](http://heldesk-paypal.user-support.com) or whatever. Never trust emails.
