# Is this PayPal/SDMB thing legit or phishing?

**URL:** <https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431>\
**Category:** Factual Questions\
**Created:** [August 4, 2011, 5:06am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431 "2011-08-04T05:06:36Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Oslo\_Ostragoth](https://avatars.discourse-cdn.com/v4/letter/o/a9a28c/32.png) [@Oslo\_Ostragoth](https://boards.straightdope.com/u/Oslo_Ostragoth)\
**Post date:** [August 4, 2011, 5:06am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/1 "2011-08-04T05:06:36Z")

</div>

I have a PayPal account that, as far as I can recall, has only been used to pay my SDMB subscription. I got this email:

"So we can continue providing you with your account information electronically please provide your consent to our Electronic Communications Delivery Policy. Log in to your PayPal account and follow the steps below.

Hello xxxxxxxxxxx,

PayPal is updating the way we send you your account information. Please agree to our Electronic Communications Delivery Policy today. This ensures that we can continue providing you with your account information electronically, including transaction receipts, account statements, and annual disclosures."

And so on and so forth.

What’s going on here?

---

<div class="post-metadata">

**Author:** ![silenus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/silenus/32/166_2.png) [@silenus](https://boards.straightdope.com/u/silenus)\
**Post date:** [August 4, 2011, 5:12am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/2 "2011-08-04T05:12:17Z")

</div>

It a phish. If you check the url on mouseover, it doesn’t go to [paypal.com](http://paypal.com), but [e.paypal.com](http://e.paypal.com).

Totally bogus. Delete it. Paypal will never contact you by email. They only contact you by message when you log in.

---

<div class="post-metadata">

**Author:** ![DMC](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dmc/32/18049_2.png) [@DMC](https://boards.straightdope.com/u/DMC)\
**Post date:** [August 4, 2011, 5:20am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/3 "2011-08-04T05:20:40Z")

</div>

> [@silenus](#):
>
> It a phish. If you check the url on mouseover, it doesn’t go to [paypal.com](http://paypal.com), but [e.paypal.com](http://e.paypal.com).

Are you sure that it is [e.paypal.com](http://e.paypal.com)? If so, that’s just a subdomain, so I’m not sure how this particular phishing method would work. If it’s something like [e-paypal.com](http://e-paypal.com), [epaypal.com](http://epaypal.com), [e.paypal.com.something.com](http://e.paypal.com.something.com) etc., then sure.

---

<div class="post-metadata">

**Author:** ![DMC](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dmc/32/18049_2.png) [@DMC](https://boards.straightdope.com/u/DMC)\
**Post date:** [August 4, 2011, 5:23am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/4 "2011-08-04T05:23:42Z")

</div>

By the way, I’ll agree that that message smells fairly phishy. I’m just confused on how that would work if the domain is actually what **silenus** stated.

---

<div class="post-metadata">

**Author:** ![silenus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/silenus/32/166_2.png) [@silenus](https://boards.straightdope.com/u/silenus)\
**Post date:** [August 4, 2011, 5:24am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/5 "2011-08-04T05:24:30Z")

</div>

e-something. I checked it and deleted it because as I noted Paypal never contacts anyone by email. Ever.

---

<div class="post-metadata">

**Author:** ![DMC](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dmc/32/18049_2.png) [@DMC](https://boards.straightdope.com/u/DMC)\
**Post date:** [August 4, 2011, 5:29am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/6 "2011-08-04T05:29:19Z")

</div>

Yes, if it is [e-paypal.com](http://e-paypal.com), that’s likely someone phishing. [e.paypal.com](http://e.paypal.com), on the other hand, should be completely legit.

**Oslo Ostragoth** , if there are links in the email to “login” or “accept”, etc., then probably a phishing attempt. If it just directs you to log onto paypal yourself, without any links to “help” you get there, probably legit.

---

<div class="post-metadata">

**Author:** ![running\_coach](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/running_coach/32/15836_2.png) [@running\_coach](https://boards.straightdope.com/u/running_coach)\
**Post date:** [August 4, 2011, 5:34am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/7 "2011-08-04T05:34:13Z")

</div>

Legit or not, you won’t get in trouble by going to the site on your own(no link clicking) and login as you usually do.

---

<div class="post-metadata">

**Author:** ![psychonaut](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/psychonaut/32/4655_2.png) [@psychonaut](https://boards.straightdope.com/u/psychonaut)\
**Post date:** [August 4, 2011, 5:38am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/8 "2011-08-04T05:38:50Z")

</div>

> [@silenus](#):
>
> e-something. I checked it and deleted it because as I noted Paypal never contacts anyone by email. Ever.

I don’t know where you got this idea; PayPal contacts people by e-mail all the time for various reasons, such as when they’ve received a payment.

---

<div class="post-metadata">

**Author:** ![johnpost](https://avatars.discourse-cdn.com/v4/letter/j/f17d59/32.png) [@johnpost](https://boards.straightdope.com/u/johnpost)\
**Post date:** [August 4, 2011, 6:01am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/9 "2011-08-04T06:01:01Z")

</div>

if it’s legit and you need to do something then when you log on to PayPal it will give you a message saying you need to do something.

---

<div class="post-metadata">

**Author:** ![paperbackwriter](https://avatars.discourse-cdn.com/v4/letter/p/53a042/32.png) [@paperbackwriter](https://boards.straightdope.com/u/paperbackwriter)\
**Post date:** [August 4, 2011, 6:08am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/10 "2011-08-04T06:08:16Z")

</div>

> [@silenus](#):
>
> e-something. I checked it and deleted it because as I noted Paypal never contacts anyone by email. Ever.

BS. Paypal is actually asking for permission to do exactly that. If you’re paranoid, instead of following any links in the e-mail, just type [www.paypal.com](http://www.paypal.com) into a new browser window and sign on. Lo and behold, you’ll get a request to approve electronic document delivery.

Y’know, so Paypal has your permission to contact you by e-mail. [But you don’t have to take my word for it](https://cms.paypal.com/us/cgi-bin/?cmd=_render-content&content_ID=ua/archive_policies_full&fli=true&locale.x=en_US):

> [@](#):
>
> Notices to You. We have modified our disclosures about the notices we send to you in Section 1, which we will now provide to you in a separate disclosure called “Electronic Communications Delivery Policy” which can be accessed by clicking on the Legal Agreements link at the bottom of the PayPal website. \*\*This policy describes how we communicate with you electronically, \*\*provides additional detail about the Communications we provide to you, and sets out the hardware and software you need to receive these Communications.

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [August 4, 2011, 6:40am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/11 "2011-08-04T06:40:43Z")

</div>

It’s legit. Go to [Paypal.com](http://Paypal.com) manually, and they’ll ask you the same thing.

BTW, [e.paypal.com](http://e.paypal.com) is their email sending server.

---

<div class="post-metadata">

**Author:** ![An\_Gadai](https://avatars.discourse-cdn.com/v4/letter/a/d6d6ee/32.png) [@An\_Gadai](https://boards.straightdope.com/u/An_Gadai)\
**Post date:** [August 4, 2011, 7:26am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/12 "2011-08-04T07:26:48Z")

</div>

> [@silenus](#):
>
> e-something. I checked it and deleted it because as I noted Paypal never contacts anyone by email. Ever.

Yes they do, all the time.

---

<div class="post-metadata">

**Author:** ![Shakester](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/shakester/32/437_2.png) [@Shakester](https://boards.straightdope.com/u/Shakester)\
**Post date:** [August 4, 2011, 10:52am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/13 "2011-08-04T10:52:25Z")

</div>

Yep, I get emails from PayPal too.

What they **don’t** do is provide links in emails, so any email that asks you to click on a link to log in is bogus. But send emails? Of course they do.

---

<div class="post-metadata">

**Author:** ![EvilTOJ](https://avatars.discourse-cdn.com/v4/letter/e/ee59a6/32.png) [@EvilTOJ](https://boards.straightdope.com/u/EvilTOJ)\
**Post date:** [August 4, 2011, 11:07am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/14 "2011-08-04T11:07:52Z")

</div>

It’s possibly a scam. I got this email too, complete with link to click. Only, I didn’t get it to the email address I use with PayPal. When I went to [paypal.com](http://paypal.com) and logged in manually, I got;

> [@](#):
>
> Electronic Communications Delivery Policy (E-Sign Disclosure and Consent)  
> We’d like to continue providing you information about your account electronically such as through email, web pages, and .pdf files.
> 
> In order for us to continue sending you information about your account electronically, please read and accept our Electronic Communications Delivery Policy today.
> 
> I have read the Electronic Communications Delivery Policy (E-Sign Disclosure and Consent) and agree that PayPal may provide information to me about my PayPal account electronically. I confirm that I can access and print or save emails, web pages and .pdf files that PayPal sends or otherwise makes available to me.

So it could be legit, or it could be phishers knowing paypal sent out an update and they’re playing on that.

---

<div class="post-metadata">

**Author:** ![Fear\_Itself](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/fear_itself/32/19637_2.png) [@Fear\_Itself](https://boards.straightdope.com/u/Fear_Itself)\
**Post date:** [August 4, 2011, 11:49am UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/15 "2011-08-04T11:49:17Z")

</div>

> [@Shakester](#):
>
> What they **don’t** do is provide links in emails, so any email that asks you to click on a link to log in is bogus. But send emails? Of course they do.

And they always address you by your PayPal user name, not some ambiguous, “Dear PayPal User:”

---

<div class="post-metadata">

**Author:** ![silenus](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/silenus/32/166_2.png) [@silenus](https://boards.straightdope.com/u/silenus)\
**Post date:** [August 4, 2011, 5:09pm UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/16 "2011-08-04T17:09:50Z")

</div>

I sit corrected.

But this one is a phish, because it’s to “Paypal user,” not whatever my name is on Paypal. And it’s sent to my Hotmail account, which isn’t the one I use for Paypal. So I was right that it was bogus, just for the wrong reason.

Just like normal. 😃

---

<div class="post-metadata">

**Author:** ![pulykamell](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/pulykamell/32/3166_2.png) [@pulykamell](https://boards.straightdope.com/u/pulykamell)\
**Post date:** [August 4, 2011, 7:22pm UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/17 "2011-08-04T19:22:11Z")

</div>

[QUOTE=Shakester;14099820  
What they **don’t** do is provide links in emails, so any email that asks you to click on a link to log in is bogus. But send emails? Of course they do.[/QUOTE]

Not sure what you mean. All my Paypal receipts and shipment notices have hotlinks in them.

---

<div class="post-metadata">

**Author:** ![MeanOldLady](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/meanoldlady/32/10737_2.png) [@MeanOldLady](https://boards.straightdope.com/u/MeanOldLady)\
**Post date:** [August 4, 2011, 8:11pm UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/18 "2011-08-04T20:11:04Z")

</div>

> [@silenus](#):
>
> I sit corrected.
> 
> But this one is a phish, because it’s to “Paypal user,” not whatever my name is on Paypal. And it’s sent to my Hotmail account, which isn’t the one I use for Paypal. So I was right that it was bogus, just for the wrong reason.
> 
> Just like normal. 😃

Yours was a phish, but I got the same e-mail the OP describes with my name.

> [@Shakester](#):
>
> What they **don’t** do is provide links in emails…

Yes they do.

---

<div class="post-metadata">

**Author:** ![Uber\_the\_Goober](https://avatars.discourse-cdn.com/v4/letter/u/58956e/32.png) [@Uber\_the\_Goober](https://boards.straightdope.com/u/Uber_the_Goober)\
**Post date:** [August 4, 2011, 8:48pm UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/19 "2011-08-04T20:48:29Z")

</div>

If you’re worried - and you have Chrome as your browser - then when you go to the website just look in the address bar. It says (with a green box around it) the name of the company, and shows that it is indeed a secure connection to the website you actually intended to go to.

Another reason I like Chrome.

---

<div class="post-metadata">

**Author:** ![ZipperJJ](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/zipperjj/32/211_2.png) [@ZipperJJ](https://boards.straightdope.com/u/ZipperJJ)\
**Post date:** [August 4, 2011, 8:56pm UTC](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431/20 "2011-08-04T20:56:09Z")

</div>

> [@echo6160](#):
>
> If you’re worried - and you have Chrome as your browser - then when you go to the website just look in the address bar. It says (with a green box around it) the name of the company, and shows that it is indeed a secure connection to the website you actually intended to go to.
> 
> Another reason I like Chrome.

Glad you like Chrome but Firefox 3+ does this, as does IE 8+. As long as the site you’re on is a secure site.

[Next page](https://boards.straightdope.com/t/is-this-paypal-sdmb-thing-legit-or-phishing/591431.md?page=2)
