Why the email looked real
This scam is unusually convincing because the notification can be sent through actual DocuSign infrastructure. The message may pass email authentication, use real DocuSign branding, and link first to a legitimate DocuSign page. Those facts verify the delivery service—not the identity or intentions of the person who created the envelope.
Inside the request, the supposed sender may appear as “Accounts Payable” or use an address resembling quickbooks-notification.intuit.com@fmqlv.com. Everything after the final @ is the sender’s domain. In that example, the domain is fmqlv.com, not intuit.com or quickbooks.com.
DocuSign has warned about this exact pattern
DocuSign’s own Safety Center describes a campaign impersonating Intuit QuickBooks with unexpected invoices or remittance advice. Their examples use a sender format like quickbooks-notification.intuit.com@[random-domain].com and may originate from the real DocuSign platform.
What to do now
- Do not approve, sign, download, call, or pay anything from the request.
- Contact the supposed vendor using a phone number or address already in your records—not information inside the email.
- Go directly to DocuSign rather than using the email button if you need to inspect the envelope.
- Forward the suspicious email as an attachment to verify@docusign.com.
- If this reached a work or school inbox, report it to your IT team so they can look for other recipients.
The important lesson
“The sender domain is real” is no longer enough. Criminals routinely abuse trusted services such as DocuSign, Microsoft 365, Google Drive, Dropbox, and legitimate marketing platforms. Verify the human request and the business relationship—not merely the logo or delivery system.
