I figured out the scam and wrote it up here: reddit.com/r/Scams/comments/1j?

Basically, they set up their merchant account with a merchant name that is literally, "If you do not recognize the seller, please contact.." hoping you don't notice all the other wrong details. But this does get them a legit email with a digital signature signed by the real paypal.com, which they forward to you.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.social/users/AlSweigart/statuses/114151385316920505 on your instance and quote it. (Note that quoting is not supported in Mastodon.)