You click on the link in the email, that leads you to a FAKE login page, you log in there and it redirects you to the real paypal. But in the mean time these friendly (russian or nigerian mostly) people will also have your password for it.
So always check if the url bar says https://www.paypal.com
Or whatever else the official site for a bank is, sometimes it might look pretty similar but rarely will it also use https:// instead of http://
The https:// part means that your passwords are transmitted securely, and it is a lot harder to fake a site that uses it (all online banking and paypal do)