DocuSign is a common phishing target because a document waiting for signature feels urgent and official. Fake messages copy the branding, but the link leads to credential theft or a malicious download.
Does this affect you?
Use this for any personal or work email claiming a DocuSign document is ready to view, review, or sign, especially if you were not expecting one.
Check whether the email is real
Do this before clicking View Document or Review Document.
- Check the sender’s actual email address, not only the display name. Genuine DocuSign notifications commonly use the docusign.net domain.
- Hover over the document button on a computer and inspect the destination. Avoid links that do not go to docusign.net or docusign.com.
- Ask whether you were expecting a document. Real senders often mention it in a separate conversation first.
- Watch for generic greetings, urgent 24-hour deadlines, and requests for your email password or payment details.
- If unsure, go directly to docusign.com and sign in there, or contact the supposed sender through a known phone number or email thread.
If you clicked or entered information
Act quickly, especially if a password or download was involved.
- If you entered a DocuSign, email, or work password, change it immediately on the real site.
- Change that password anywhere else it was reused.
- If you downloaded and opened a file, disconnect the device and run a full antivirus scan before reconnecting.
- Check your email forwarding rules, recovery information, and connected apps for changes you did not make.
- Turn on two-factor authentication for email if it was not already active.
- Report the phishing email to DocuSign through the reporting address or process listed in the DocuSign Trust Center.
More control
Other e-signature brands get copied too
Adobe Sign, Dropbox Sign, and similar services are impersonated with the same pattern. Verify sender domain, hover before clicking, and use the real site directly.
No signature service needs your email password
A document-view page asking for your mailbox password is one of the clearest signs of phishing.
Confirm sensitive documents separately
If the email claims to come from a bank, employer, landlord, or vendor, contact that organization through a known channel before opening it.
Sources
- DocuSign Trust Center – Report phishing and suspicious emails (2025)
- DocuSign – How to recognize fake DocuSign emails and websites (2025)
- FTC Consumer Advice – How to recognize and avoid phishing scams (2025)
