>This email honestly was formatted to look like a legit PayPal email,
this is why anything but plain text should be blocked in emails (besides security reasons). anybody with 5 minutes of HTML experience can create "legit looking" emails.
It was an actual email sent by PayPal via a service they propose (sending invoices), just with a smartly crafted company name that made it look it's from them. No HTML was required from the attacker.
this is why anything but plain text should be blocked in emails (besides security reasons). anybody with 5 minutes of HTML experience can create "legit looking" emails.