I think there may be a way to prevent being scammed. Please tell me if this works.
After the payment is made through Paypal, ask the buyer to send back the Paypal receipt. After the receipt is received by you and you confirm it with your own copy, that will indicate the person is the rightful owner of the account. Then you can transfer the domain over.
Since a scammer will most likely not have access to the email account which belongs to the owner of the Paypal account being stoled, the scammer will not be able to receive the receipt sent by Paypal.
Would this work?
Anthony
