For the record, not overly happy with the response, I've sent this follow-up to spoof@paypal.com:
>Hi there. Thanks for the quick response.
I do have a question.
Why would PayPal refer me to a form not hosted under PayPal domain? How can I tell it's a legit PayPal communication?
Would it be possible for you to post the source (or even just the headers) with your email scrubbed from the message you received from them the first time? Depending on your email provider they could fake that too but it might be worth a look.
>Hi there. Thanks for the quick response. I do have a question. Why would PayPal refer me to a form not hosted under PayPal domain? How can I tell it's a legit PayPal communication?
Expectedly, never got a response.