The only reason why companies don't care about it in the context of mail is because there is no equivalent to safe browsing for mails, so Domains aren't penalized by Google for sending fraudulent messages at small scale. If this was to change, they'd all pivot to using secondary domains for these mails, like GitHub does for GitHub pages.
It would also be a pretty pointless feature as you'd probably complain anyway, as the email would still come from a Paypal owned domain.
On the same topic: if you've got a Gmail address you're also able to send from @googlemail.com
Is this another security issue in your opinion?
Nor does it matter wherever it's a clickable link or text in this context. The only way to "solve" your issue is by removing user generated content, which makes the invoicing feature inherently impossible.
If you're seriously shocked that PayPal isn't decommissioning a highly profitable feature because a random carebear worries about their family... Then you're honestly out of touch with reality.
Most people nowadays know that emails are untrustworthy, and if your family doesn't... Then you should tell them that, as they're bound to get scammed eventually if they click on any links from their inbox.
paypal in a URL pointing to a non-paypal domain, no need to load the webpage to flag that.