Domain Trust Report • Financial Services & Payment Processing

paypal.com Security Audit & Domain Trust Score

Inspect paypal.com email security posture, anti-phishing DMARC p=reject enforcement, DigiCert EV SSL certificates, and official DNS records.

Quick Answer • paypal.com Security Posture Rating

paypal.com operated by PayPal Holdings, Inc. maintains an A+ Trust Rating (99/100). The domain enforces strict DMARC policy (p=reject; sp=reject; pct=100), uses 2048-bit RSA DKIM signatures, and is encrypted with TLS 1.3 certificates issued by DigiCert Global Root CA.

Live Security Audit for paypal.com

Execute a live multi-protocol audit across DNS, SPF, DKIM, DMARC, and TLS handshake sockets.

Live DNS Probe

Security Architecture Overview: paypal.com

PayPal was one of the founding co-authors of the DMARC protocol (RFC 7489) following years of being the most targeted financial brand in phishing history. Today, PayPal maintains one of the strictest anti-phishing postures in the industry.

Key Anti-Spoofing & Cryptographic Highlights

Pioneer DMARC Enforcement: Set to p=reject across all root domains and subdomains (sp=reject).
EV SSL & Strict HSTS: Enforces HTTP Strict Transport Security with preloaded subdomains and 1-year max-age.

Frequently Asked Questions

Why is PayPal's DMARC policy significant?

PayPal co-developed DMARC after suffering massive phishing attacks in the 2000s. Their p=reject deployment eliminated over 99% of direct @paypal.com email spoofing.

Does paypal.com protect subdomains with DMARC?

Yes. PayPal's DMARC record includes sp=reject, which extends full p=reject protection to all subdomains (e.g. mail.paypal.com, alerts.paypal.com), preventing attackers from registering look-alike subdomains for phishing.

What SSL certificate does paypal.com use?

PayPal.com uses DigiCert Global Root CA-issued EV (Extended Validation) certificates. EV certificates require the Certificate Authority to validate organizational identity through legal documents, providing the highest commercially available identity assurance.

How do I confirm a payment email from PayPal is real?

Authentic PayPal emails originate from @paypal.com or @e.paypal.com, pass both SPF and DKIM with d=paypal.com, and pass DMARC. Use IncogSay's Email Header Analyzer to inspect headers and confirm all three pass.

What is PayPal's SPF record?

PayPal uses a delegated SPF record via include:pp._spf.paypal.com, which resolves to PayPal's authorized sending infrastructure. The top-level record terminates with ~all (softfail), but DMARC p=reject provides the enforcement layer.

When did PayPal help develop DMARC?

PayPal was one of the founding industry contributors to the DMARC.org specification process in 2011-2012, alongside Google, Microsoft, and Yahoo. The RFC 7489 specification was formally published in 2015.