Bewary Get Bewary
Scam patternPublished Sep 15, 2026

Is this DocuSign email real or a phishing scam?

Bewary fraud research, published by Andrey Khayrullaev, founder. How we research scam patterns.

Example email

From: DocuSign <notifications@docusign-secure.net> Subject: Action Required: Completed Agreement Needs Your Signature Hello, You have received a secure document from Accounts Payable. Please review and sign the attached agreement before 5:00 PM today to avoid cancellation of invoice payment. Document: Q4 Vendor Remittance Authorization.pdf Envelope ID: 8291741 Review Document: https://docusign-secure.net/envelope/8291741 For mobile access, open the attached PDF and scan the QR code. This secure envelope will expire in 24 hours. If prompted, sign in with your Microsoft 365 or Gmail account to verify your identity.

SCAM

Fake if DocuSign becomes mailbox login. DocuSign signing notices use an envelope flow, and legitimate notices include a security code you can use from docusign.com instead of trusting the button in the email. The structural tell is the handoff: a message that starts as a signature request, then asks for Microsoft 365, Gmail, a PDF download, or a QR scan, has left the DocuSign signing path.

How to spot the DocuSign scam

  • Use the security code to reach the envelope from DocuSign.Why
  • Reject any notice that turns signing into a Microsoft 365 or Gmail login.Why
  • Treat a PDF with a QR code as outside the DocuSign flow.Why
  • Require a DocuSign notification domain, not a DocuSign-looking word.Why
  • Reject an email that says completed and still demands your signature.Why
  • Refuse attachments that replace the envelope.Why
  • Do not use an access page that asks for your email password first.Why
  • Do not clear a DocuSign notice just because SPF, DKIM, or DMARC passed.Why

What to do now

  1. Open docusign.com and use the security code from the email.Why
  2. Forward the suspicious email to spam@docusign.com.Why
  3. Ask the named sender to void and resend the envelope inside DocuSign.Why
  4. If you scanned the QR code, send IT the PDF and the phone URL.Why
  5. If you typed a Microsoft 365 or Google password, revoke sessions now.Why
  6. If you clicked a fake DocuSign page, capture the URL before closing it.Why
  7. If you signed, pull the Certificate of Completion and freeze the workflow.Why

What it looks like on your phone

Recreated example of the DocuSign scam email: From: DocuSign <notifications@docusign-secure.net>
Subject: Action Required: Completed Agreement Needs Your Si
A representative example based on common reports. Exact wording varies.

Got a message like this? Check yours free

Paste any text, link, or number you are unsure about. Bewary gives you a straight answer in seconds, and the exact reason why.

Private. Never sold, never tied to you.

The detail behind this

The reasoning behind each line above, for when the immediate question is settled.

Why each of those gives it away

Use the security code to reach the envelope from DocuSign.

Real DocuSign signing emails include a security code that lets you access the envelope without trusting the email button. Many fakes skip it, shorten it into a fake envelope ID, or put a code only on the phishing page because there is no real DocuSign envelope behind the message.

Reject any notice that turns signing into a Microsoft 365 or Gmail login.

The scam needs your mailbox password, not your signature. Once it has that password, the next move is usually inbox access, invoice-thread theft, and payment-change messages sent from your real account.

Treat a PDF with a QR code as outside the DocuSign flow.

The fake attachment usually says mobile review is required or the document is protected. That moves you from a monitored work browser to a phone camera and a phone browser, where the fake Microsoft or Google login screen gets fewer security checks.

Require a DocuSign notification domain, not a DocuSign-looking word.

A sender like notifications@docusign-secure.net is built to win the first glance, but the root domain is docusign-secure.net, not DocuSign. Real DocuSign notification mail is tied to DocuSign domains such as docusign.net or docusign.com, not a hyphenated copycat sitting after the @ sign.

Reject an email that says completed and still demands your signature.

That wording conflict shows the sender is copying DocuSign language without understanding the envelope state. A completed envelope is not the same event as a new envelope waiting for your signature, and scammers mix the terms because one template gets reused for AP, HR, legal, and payroll lures.

Refuse attachments that replace the envelope.

A DocuSign signing notice should send you into an envelope review, not make you open Q4 Vendor Remittance Authorization.pdf to begin. The attachment version gives the attacker a place for a QR code, a fake button, or a malware prompt while still borrowing DocuSign trust from the email subject line.

Do not use an access page that asks for your email password first.

Some fake pages copy DocuSign colors, then put Microsoft 365, Gmail, or company email buttons in the center. That is the payload. The attacker wants a reusable login, not a one-time signature decision inside an envelope.

Do not clear a DocuSign notice just because SPF, DKIM, or DMARC passed.

Attackers can abuse a real DocuSign account, a compromised sender, or an API path, so email authentication may only prove the message came through an allowed channel. It does not prove the business request, the signer, or the destination page is safe.

Working through the steps

Open docusign.com and use the security code from the email.

Use DocuSign’s own access path instead of the Review Document button. If the message has no usable security code, that is evidence by itself, because the email is asking you to trust a link while withholding the DocuSign detail that lets you bypass it.

Forward the suspicious email to spam@docusign.com.

Send the original message, not a screenshot, so DocuSign can see the sender, links, and attachment behavior. This is DocuSign’s published reporting route for suspicious DocuSign-branded email.

Ask the named sender to void and resend the envelope inside DocuSign.

Do not ask them to explain the old email thread. A clean resend creates a fresh envelope, fresh notification, and fresh security code, which breaks the attacker’s copied link, QR page, or abused template.

If you scanned the QR code, send IT the PDF and the phone URL.

The phone visit is part of the evidence because the QR page may differ from the desktop link. Include the time you scanned it and whether it asked for Microsoft 365, Gmail, a download, or a browser permission.

If you typed a Microsoft 365 or Google password, revoke sessions now.

Change the password from the real account portal, then have IT remove active sessions, new MFA methods, mail forwarding rules, inbox delegates, and suspicious sign-in tokens. The danger is not the DocuSign email anymore. It is the mailbox the attacker may already be using.

If you clicked a fake DocuSign page, capture the URL before closing it.

Do not keep interacting with the page, download the offered file, or approve a browser prompt. The exact URL helps IT block the phishing host and check whether the page only collected visits or tried to push a file.

If you signed, pull the Certificate of Completion and freeze the workflow.

DocuSign’s certificate shows envelope details such as recipients, timing, and audit events, which helps separate a real envelope from a copied lure. Stop any invoice, payroll, vendor, or contract action tied to that envelope until the sender voids or confirms it from inside DocuSign.

Sources and reporting

Use official channels to confirm a suspicious request and report fraud.