Security Architecture Overview: paypal.com
PayPal was one of the founding co-authors of the DMARC protocol (RFC 7489) following years of being the most targeted financial brand in phishing history. Today, PayPal maintains one of the strictest anti-phishing postures in the industry.
Key Anti-Spoofing & Cryptographic Highlights
Frequently Asked Questions
Why is PayPal's DMARC policy significant?
PayPal co-developed DMARC after suffering massive phishing attacks in the 2000s. Their p=reject deployment eliminated over 99% of direct @paypal.com email spoofing.
Does paypal.com protect subdomains with DMARC?
Yes. PayPal's DMARC record includes sp=reject, which extends full p=reject protection to all subdomains (e.g. mail.paypal.com, alerts.paypal.com), preventing attackers from registering look-alike subdomains for phishing.
What SSL certificate does paypal.com use?
PayPal.com uses DigiCert Global Root CA-issued EV (Extended Validation) certificates. EV certificates require the Certificate Authority to validate organizational identity through legal documents, providing the highest commercially available identity assurance.
How do I confirm a payment email from PayPal is real?
Authentic PayPal emails originate from @paypal.com or @e.paypal.com, pass both SPF and DKIM with d=paypal.com, and pass DMARC. Use IncogSay's Email Header Analyzer to inspect headers and confirm all three pass.
What is PayPal's SPF record?
PayPal uses a delegated SPF record via include:pp._spf.paypal.com, which resolves to PayPal's authorized sending infrastructure. The top-level record terminates with ~all (softfail), but DMARC p=reject provides the enforcement layer.
When did PayPal help develop DMARC?
PayPal was one of the founding industry contributors to the DMARC.org specification process in 2011-2012, alongside Google, Microsoft, and Yahoo. The RFC 7489 specification was formally published in 2015.