Why signature requests are a phishing favorite

A "please sign this document" email is almost perfectly designed for social engineering. It carries built-in urgency (someone's waiting on you), it's routine enough that people click without scrutiny, and it legitimately contains a link you're supposed to follow. Attackers know this, so fake signing requests — imitating well-known e-signature brands — are a common phishing lure. The goal is usually to send you to a credential-harvesting page dressed up as a login, or to a malware download disguised as "the document."

The good news: a genuine signing request has a specific, checkable shape, and a fake one almost always breaks it somewhere. This is a practical guide to telling the two apart before you click — and it pairs with the sender-side view in what happens after you sign and verifying a signed document you received.

First, slow down — urgency is the tell

The single most useful habit is to notice the pressure. Phishing leans on urgency: "signature required today," "your account will be suspended," "final notice." A real signing request can have a deadline, but it won't threaten your account or manufacture panic. If a message makes you feel you must act right now or something bad happens, that feeling is the reason to slow down, not speed up.

Check who it's actually from

Look at the real sender address, not just the display name. Display names are trivial to fake ("DocuSign" or "Document Service" in the from-line means nothing). Expand the actual email address and ask: does it come from the platform you'd expect, or from a lookalike domain with an extra word, a hyphen, or a different top-level domain? Then ask the more important question: were you expecting this? A legitimate signing request almost always corresponds to something real — a contract you're negotiating, an onboarding packet you know is coming, a vendor you deal with. A signing request from a company you've never heard of, for a document you don't recognize, is suspicious by default.

Hover the link before you click

Before clicking anything, hover over the button or link and read where it actually goes (on mobile, press and hold to preview the URL). A genuine request from a real platform will link to that platform's own domain. Watch for:

  • A domain that contains a trusted brand name but isn't actually it (docusign.secure-verify.com is not DocuSign)
  • Raw IP addresses, random-looking subdomains, or link-shorteners hiding the destination
  • Mismatches between the brand in the email and the domain in the link

If the destination doesn't clearly belong to the platform the email claims to be from, don't click it.

Know what a real request will — and won't — ask you to do

This is the clearest signal of all, because it doesn't depend on spotting a subtle domain typo. A legitimate e-signature flow has boundaries:

  • It won't ask for your password to another service. You don't need your email password, your bank login, or your company SSO credentials to view and sign a document. Any signing page asking for those is a harvesting page.
  • It won't demand payment to "release" a document. Signing a document is not a paywall. (Collecting a payment as part of a legitimate signing flow is a real feature — but that's an expected, itemized charge inside a request you initiated, not a surprise fee to unlock a mystery file.)
  • It won't require you to download and run an executable. A real document opens in the browser. "Download this .zip / enable macros / run this to view" is malware, not a contract.
  • Identity checks, if any, are lightweight and expected. A legitimate request might ask for an access code the sender gave you or an SMS passcode — a short code, delivered out-of-band, that you were told to expect. It will never ask you to "verify" by entering full banking or login credentials.

Verify out-of-band when in doubt

If you're unsure and the document seems like it could be real, don't resolve it by clicking. Contact the supposed sender through a channel you already trust — a phone number or email you have on file, not the contact details in the suspicious message. "Did you just send me something to sign?" takes thirty seconds and closes the loop safely. A real sender will happily confirm; a phishing campaign has no one to answer.

What this looks like from the sender's side

If you send signing requests, you can make your own requests easier to trust — which protects your recipients and your response rates. Branding the signing email and page with your logo and colors gives recipients a consistent, recognizable signal. Telling signers in advance ("you'll get a request from us to sign the agreement") turns an unexpected email into an expected one. And when a signer says they never got it or isn't sure it's real, the guidance in the signer didn't receive the email helps you resolve it without them clicking anything doubtful.

The takeaway

Treat every signature request with the same calm scrutiny you'd give any unexpected email. Slow down when it feels urgent; check the real sender address and whether you were expecting the document; hover the link to confirm it goes to the platform's own domain; and remember the boundaries — a real signing flow never needs your password to another service, never charges a surprise fee to unlock a file, and never asks you to download and run a program. When in doubt, verify with the sender through a channel you already trust. Once you've confirmed a request is genuine, you can sign it with confidence and keep the audited, verifiable record it produces.

This article is general security guidance, not legal or professional cybersecurity advice. If you believe you've entered credentials on a phishing page, change the affected passwords immediately and notify your IT or security team.