Not sure about this
"Not even PayPal support can tell the difference between a legitimate PayPal email and a phishing attack,"
Surely the embedded link that points to paypal.com.ddsrv.cz gives the game away,
Why don't Paypal and banks etc. sign their emails with pgp?
