How trusted-platform phishing works
A criminal creates or compromises an account on a legitimate service and uses that service to deliver the lure. Email security sees a valid DocuSign message because DocuSign really sent it. The dangerous part is the content submitted by the account holder.
Safest way to verify it
- Ask whether you were expecting a document from this exact person or company.
- Confirm the request through a known phone number or a fresh email—not by replying to the message.
- Navigate to docusign.com yourself and use the security code found in the email.
- Do not call phone numbers or follow payment instructions contained in an unexpected document.
- Report suspicious messages to your IT team and DocuSign.
What a legitimate sender proves
A valid @docusign.net notification can prove that DocuSign delivered the envelope. It does not prove that “Accounts Payable,” “QuickBooks,” your boss, a vendor, or another displayed identity actually initiated a legitimate business transaction.
