he's receiving emails from a fraudulent account that was set up with his email address but with a "." in it. I can't see the vulnerability there but it is important to point out. Paypal should be aware that Gmail allows it. I just created 3 different paypal accounts with the three different email addresses that only differ by the position of the dot.