untrappable.Check

DocuSign email scam: is that document real?

Yes — this is a scam. DocuSign never sends documents from “docusign-verify[.]info”.

Exhibit · Email

You have a document waiting — action required
D
DocuSign
no-reply@docusign-verify[.]info
10:42 AM
A document was sent to you for signature and expires in 24 hours. Review and sign now to avoid cancellation: docusign-verify[.]info/review
Review document

Other versions you might get: A fake “your account has been suspended” notice, a shared invoice or contract from a name you half-recognize, or a “voicemail” or “fax” attachment that's really a phishing link.

What to do right now

  1. Don't click the link or button, and don't open any attachment.
  2. Check independently. Verify the sender through a contact you already trust. Docusign lets recipients use its Access Documents route and an alternate signing code without an account; a document missing from your own account is not proof it is fake.
  3. Report it. File at reportfraud.ftc.gov and mark the email as phishing.
  4. Delete it so you don't tap it later by mistake.
  5. If you already tapped and entered your login, change that password now, turn on two-factor, and check any account that used the same password.

Reduce the risk of another scam

Do not use the message’s link to check the claim. Open the real service yourself. If you paid or shared account details, start with what to do after a scam. Blocking and reporting can reduce unwanted contact, but they cannot stop every attempt or tell you how the sender found you.

● Public service · free steps first

Take the free protection steps first

A suspicious message does not tell us how someone found your details. If you shared personal information, start with the official recovery guidance. You can also freeze your credit for free.

Decide what protection you need

Start with the free controls above. Compare what a paid service would add only after deciding which problem remains.

Frequently asked

How can I tell a real DocuSign email from a fake one?
First verify the sender and expected document through a known contact. A legitimate Docusign envelope may arrive by email and may expire; neither a signing link nor a deadline proves fraud. You can open docusign.com independently and use Access Documents with the email’s alternate signing code. You do not need an account to sign.
The email says the document expires in 24 hours — should I sign fast?
No. The countdown is a pressure tactic, not a real deadline. Phishing messages manufacture urgency — “action required,” “expires soon,” “account on hold” — so you click before you check. A genuine agreement doesn't punish you for pausing. Slow down, verify at docusign.com directly, and if you weren't expecting it, report and delete it.
I clicked the DocuSign link and entered my login — what should I do?
Change that password right now, and turn on two-factor (multi-factor) authentication — the FTC recommends it because it makes a stolen password much harder to use. Change the password anywhere else you reused it, too. If you opened an attachment, update your security software and run a scan. Forward the phishing email to reportphishing@apwg.org and report it at reportfraud.ftc.gov.

Sources

  1. 01How To Recognize and Avoid Phishing Scams— Federal Trade Commission
  2. 02Frequently asked questions about Docusign eSignature— docusign.com
  3. 03Official security and fraud guidance— docusign.com

Pass it on

Help protect someone else

If this could have fooled you, it can fool someone you know — a parent, a friend, the family group chat. It's safe to forward, and stands on its own as a record for a bank or the police.