About this question
I have just received a message asking to consent to PayPal policy updates from the domain:
https://epl.paypal-communication.com
The actual link is full of trackers. Given the domain name, it sounds like a routine email spoof. Also, visiting the domain, you receive a "503 Service Unavailable" message.
After some investigations, including whois, the weird domain seems really linked to PayPal.com. That being the case:
Why should a company (and in particular a company dealing with payments) send messages from another domain like “epl.paypal-communication”? Why add countless trackers if you can already recognize users from logon?
Should the practice of sending messages from somecompany.com using anothercompany.com become established, it will be virtually impossible for us users telling if a website is legit or a scam.