“You have a document to review and sign.” If contracts are part of your work — and for freelancers and small teams they are — that email is routine. Which is exactly why fake DocuSign emails are one of the most effective phishing lures going. Here’s the domain to check, and the built-in way to open any document without touching the email at all.
Published 27 July 2026 · ~7 min read · By the Phixo team
E-signature emails occupy a strange place in your inbox: they’re unexpected by design (someone else decides when to send you a contract), they demand a click by design (that’s how signing works), and they often carry real money or legal weight. Scammers noticed. A fake DocuSign notification borrows all of that built-in legitimacy and points the “Review document” button at a credential-harvesting page instead.
The payload is usually one of two things: a fake sign-in page that asks for your email password “to view the document” — which hands over your whole inbox, not just one contract — or a malicious attachment dressed up as the document itself. Either way, the tells are consistent, and DocuSign ships a built-in safety net most people have never noticed.
Check the sender’s domain: real DocuSign envelope emails come from docusign.net addresses (like dse@docusign.net), with some account emails from docusign.com. Then use the safety net: every real DocuSign email includes a security code, usually at the bottom. Ignore the email’s links entirely, go to docusign.com → Access Documents, and enter the code — the genuine document opens with zero risk. No security code, or a code that doesn’t work? The email is fake. And remember: signing a document never requires your email password — any page demanding it is a trap.
Clever, isn’t it — the fake even copies the real dse@ prefix. But the registered domain is docusign-esign-delivery.com, not docusign.net. Read domains from the right: the part before the last dot-something is the domain that counts, and everything else is decoration.
The linked page shows a document icon behind a login form — often offering “Sign in with Google” or “Sign in with Office 365” buttons that lead to pixel-perfect fake login pages. Signing someone’s contract does not require your email credentials. The document is the bait; your inbox is the target — because whoever controls your email can reset the password on nearly everything else you use.
“This link expires within 24 hours” reads as normal document hygiene, which is why it works — but real DocuSign envelopes typically stay open for weeks, and the sender decides the deadline, not the notification. In a fake, the clock exists for one reason: to get you clicking before you check anything on this list.
“Dear User” on a document you supposedly need to sign personally is a contradiction. Real envelope emails address you by name and tell you exactly who sent the document and what it’s called. Vague sender + generic greeting + generic “Contract.pdf” = blast to a list.
Some fakes skip the link and attach “the document” directly — usually an HTML file that opens a local fake login page, or an office file that asks you to enable macros. A real DocuSign notification points you to the document on DocuSign’s site; treat an unexpected attachment claiming to be the document as hostile. This overlaps with the tricks in our guide to fake invoice emails — same family, different costume.
That verify-at-the-source habit is the same one that defeats the fake Google security alert and the fake Netflix payment email — take the email out of the equation and check with the service directly. If you want to see an email’s technical trail first, our free email header analyzer shows where it really came from and whether it passed authentication.
If you typed your email password on a fake “view document” page, treat your email account as compromised — that’s bigger than one document:
Envelope notifications come from docusign.net addresses (for example dse@docusign.net), with some account emails from docusign.com. The display name shows who sent the document; the domain after the @ is what to verify.
Use the security code near the bottom of every genuine notification: go to docusign.com, choose Access Documents, enter the code. No code, or a code that doesn’t work there, means the email is fake.
No. Recipients don’t need a DocuSign account, and no legitimate e-signature flow asks for your Gmail or Outlook password. Pages that do are harvesting your inbox login.
Forward it to spam@docusign.com, hit “Report phishing” in Gmail or Outlook, then delete it. Already entered credentials? Change that password immediately and enable two-factor authentication.
Phixo is a browser extension that checks the email open in your Gmail or Outlook against several of the signals above — brand impersonation on lookalike domains, link mismatches, sender and domain reputation, and email authentication (SPF, DKIM, DMARC) — plus an AI read of the language, and flags anything suspicious in seconds. Free plan includes 10 scans a day, no credit card. A one-time Google or Microsoft sign-in keeps your scan count tied to your account.
Install Phixo free →Your email body is never stored. Analysis happens in real time and is discarded immediately.