damn phishers!
because of the way email works, it's very easy to make it look like it was from paypal, or a bank, etc
can't remember the exact details but something along the lines of, as an email is sent it's forwarded server by server to it's destination, so the original sender will make up the address and forward it like a server would
if I get something that I'm not sure is phishing or not, I'll go and type in the website myself, rather than use links in the email