DocuSign & E-Signature Phishing Scams via Email
A phishing email dressed as a DocuSign or Adobe Sign "review and sign" notification uses a spoofed sender and a Review Document button that hides a lookalike login page, harvesting your email password and 2FA code.
Part of: DocuSign & E-Signature Phishing Scams
Last reviewed: 24 July 2026
Email is the native habitat of this scam, because a signing notification is exactly what you expect to find in your inbox. A real DocuSign or Adobe Sign envelope arrives by email, so a fake one blends in perfectly: the same logo, the same layout, the same single prominent button. Nothing about the format looks wrong.\n\nThat is the trap. In email you judge a message by how it looks, but the fraud lives in what the button actually points to and who the message truly came from — neither of which the rendered email shows you. The safe move is never to sign in from the email itself, but to open the service directly and check whether a document is genuinely waiting.
How this scam works on email
The email imitates a signing notification: brand logo, an envelope or document ID, a title chosen to fit your job — "Q3 Vendor Contract," "Invoice #4471," "Payroll Authorisation" — and one large "Review Document" button. The visible sender name reads like the real service, but the actual address behind it is a lookalike or unrelated domain, and the reply-to often differs again. Because most clients render HTML and hide the underlying link, the button's real destination stays invisible until you hover or long-press it, and it resolves to a credential-harvesting page rather than the service's own domain.\n\nThe most dangerous email variant abuses a real e-signature account: the attacker sends a genuine, correctly branded envelope, so it passes SPF, DKIM, and brand filters and lands in your inbox looking flawless. The phishing link sits inside the document as a "view file elsewhere" prompt. Once one inbox is captured, the same envelope is forwarded from that real colleague's address — a business-email-compromise cascade — and mailbox forwarding rules are quietly added to hide the replies.
Common red flags
- The visible sender name says DocuSign or Adobe Sign but the actual email address or reply-to is a lookalike or unrelated domain
- Hovering the Review Document button reveals a destination that is not the service's own site
- A signing request you were not expecting, or from a sender who has no reason to send you a document
- The email pressures you with a deadline — a contract expiring today, an invoice overdue, a delivery or payment awaiting release
- The signing page reached from the email asks for your email account password, not just your e-signature login
- A genuine-looking envelope whose only real content is a link telling you to view the document somewhere else
- A second wave of identical signing emails arriving from a real colleague's address
How to protect yourself
- Never sign in through a link or button in a signing email — open a fresh browser tab, type the service's official address yourself, and check for the document in your account
- Hover over (or long-press on mobile) the Review Document button and read the real destination domain before clicking anything
- Expand the sender's full email address and reply-to, not just the display name, and treat any lookalike domain as a fake
- Turn on phishing-resistant multi-factor authentication — an authenticator app or hardware key — on both your email and e-signature accounts
- Confirm any unexpected signing request with the named sender through a separate trusted channel, never by replying to the email
- Periodically check your mailbox for forwarding rules or filters you did not create, a hallmark of a captured inbox
How to report it
- Use your email provider's Report phishing option so the message and its headers are captured and the sender can be filtered
- Forward the email with full headers to the impersonated service's abuse address (for example, DocuSign and Adobe both publish phishing-report contacts)
- Report to your national fraud or cybercrime service, and at work notify your IT or security team so they can warn other staff
- If you entered credentials, reset the password on the real site and report the compromise to your account provider
- Preserve the original email with full headers and the button's true destination URL as evidence before deleting anything
Frequently asked questions
How do I check a signing email's real sender and link without clicking?
Expand the sender to see the full email address, not just the friendly display name — scammers spoof the name freely but the underlying address or reply-to usually exposes a lookalike domain. Then hover your cursor over the Review Document button, or long-press it on a phone, to preview the true destination. If it does not resolve to the service's own official domain, it is a phishing link, regardless of how convincing the branding looks.
The email passed my spam filter and looks completely genuine — can it still be fake?
Yes. In one common variant the attacker sends the lure through a real e-signature account, so the email genuinely originates from the trusted service and passes SPF, DKIM, and brand checks. The fraud hides inside the document as a link telling you to view the file elsewhere. Never rely on the email surviving filters as proof. Instead, ignore the email's link entirely, open the service's site yourself, and confirm a document is actually waiting in your account.
I clicked the button in the email and entered my password. What now?
Act fast. Change that password on the real site immediately, and change it anywhere you reused it. Turn on or reset multi-factor authentication and sign out all active sessions. Check your email settings for forwarding rules or filters the attacker may have added to intercept replies, and remove them. Then warn your contacts and, at work, your IT team, because a captured inbox is used to phish the people who trust you. Report it to your national fraud service.