Is an email from DocuSign or Adobe Sign asking me to review a document safe?
Fake DocuSign and Adobe Sign emails are a common phishing method. Verify the sender domain and log in directly — do not click the email link.
Last reviewed: 1 August 2026
Explanation
Scammers send convincing fake e-signature request emails mimicking DocuSign, Adobe Sign, or HelloSign. The embedded 'Review Document' button leads to a phishing page that captures your login credentials or Microsoft/Google account details. Some fake links also download malware. The emails can look nearly identical to genuine ones, including correct branding and plausible sender names. Always verify by logging into your DocuSign or Adobe Sign account directly in your browser rather than following the link in the email.
E-signature phishing is effective because these emails arrive in workplaces constantly and are designed to be actioned quickly. Attackers also know that a signing request implies something important — a contract, an HR document, a payment authorisation — so recipients hesitate to ignore it. That combination of routine and urgency is exactly what the scam borrows.
The safest workflow is to treat the email purely as a notification. If a document genuinely awaits you, it will be visible when you log in to the platform directly, or the sender can confirm it through a channel you already trust. A quick message to the supposed sender takes seconds and defeats even the most polished fake.
Common red flags
- Sender email domain does not match docusign.com or adobe.com exactly
- Urgency about a document expiring in hours
- You were not expecting any document to sign
- Clicking the link asks for your email or Microsoft/Google password
What to do now
- Do not click links in the email — go directly to the service's website
- Check the sender's full email address for misspellings
- If you clicked and entered credentials, change your password immediately
- Report the phishing email to the service and your IT team
Frequently asked questions
How do I tell a real DocuSign email from a fake one?
Real DocuSign emails come from docusign.net or docusign.com. They include a security code you set, and never ask for your password. If in doubt, log in at docusign.com directly.
What if the signing request appears to come from a colleague or client I know?
Compromised business mailboxes are often used to send phishing to the victim's own contacts, so a familiar sender proves little. Confirm with the person by phone or chat before opening any unexpected signing request.