https - the 's' just means it's a secure server.
Go to the PayPal site you know is real and click on 'log-in' - the http changes to https. They BOTH appear to be bona fide PayPal sites.
They would have put the real website in so you wouldn't get suspicious and would e-mail them your password.
My opinion: website OK, e-mail not.