PayPal reset email is dodgy
A PayPal-themed phishing email from lpstingray.com is circulating across NZ, using a blank subject and password reset language to pressure you into handing over account details.
You may receive a plain-looking email with a blank subject, sent from lpstingray.com and styled to look like PayPal. It presents itself as an urgent account notice, using the headline about resetting your password for continued access and pushing you to update your details quickly. Even without visible buttons or links in the sample, the message is designed to look like a genuine PayPal security prompt.
What gives it away is that the email system could not properly verify who really sent it. There was no working SPF, DKIM, or DMARC protection behind the message, which means the sender identity was not backed by the usual checks legitimate organisations rely on. The domain is not brand new, but it is unrelated to PayPal and has no established reason to be sending account security notices on PayPal's behalf.
The attacker is after your login details or any response that helps them move the conversation forward. If you engage, reply, or follow any instructions in the message, you could hand over account credentials and give an attacker a path into payment services, email accounts, or other business systems linked to the same password.
This has been observed across multiple Microsoft 365 tenants, which means you are unlikely to be the only one seeing it. These campaigns keep appearing because once one version starts landing in inboxes, attackers reuse the same sender domain and branding until filters catch up.
The domain the message claims to be from. Fresh registrations and known-bad reputations are the strongest technical tells of a spoofed sender.
See what a genuine PayPal message looks like, the real sender domain, the real link destination, and where to report a fake.

