If you receive a signing request you were not expecting, or the document is not what you expected, do not sign it immediately. First, check who sent it, what you are being asked to sign, and where the email came from.
Even if the signing request was sent through DottedSign, you should still make sure you recognize the sender and that the document is what you expected. This article explains what to check and what to do if a signing request looks suspicious.
- What to Check When You Receive a Signing Request
- What to Do If a Signing Request Looks Suspicious
- How to Report Suspicious or Malicious Content to DottedSign
What to Check When You Receive a Signing Request
When it’s your turn to sign, DottedSign sends a signing request to your inbox. The email shows the sender’s name and email address, the document name, and a “View & Sign” button. Before proceeding, check the following:
- Sender: Do you recognize the sender? Were you expecting a signing request from them?
- Document: Is this the document you expected to receive? If you have already opened it, make sure the content is also what you expected.
- Email domain: Check whether the email comes from one of DottedSign’s official email domains:
For the complete list of official domains, see the DottedSign Security Policy.
Note: Even if the email comes from an official DottedSign domain, make sure the sender and the document content match what you were expecting.
What to Do If a Signing Request Looks Suspicious
If you do not recognize the sender, were not expecting the document, or the document does not match what you expected, do not click links in the email, download attachments, or continue signing.
If you know the sender, contact them through a method you normally use and confirm that they sent the signing request and that the document is correct. Do not rely only on contact details provided in the email or document.
If You Have Not Clicked Any Suspicious Links
- Do not click the signing link or any other suspicious links in the email.
- Do not download unfamiliar attachments or files from the email or document.
- Do not enter your password, personal information, or other sensitive information on an unfamiliar page.
- If you confirm that the content involves fraud, malicious content, or misuse of DottedSign services, follow the instructions below to report it to DottedSign.
If You Have Already Clicked a Suspicious Link
If you clicked a suspicious link in the email, check your email account and device for unusual activity as soon as possible, and change your email password.
If you entered your login credentials on a suspicious page, check recent activity across accounts or devices that use those credentials and change the affected passwords. We also recommend changing your passwords regularly to reduce potential security risks.
If you believe the signing request involves fraud, malicious content, or misuse of DottedSign services, follow the instructions below to report it to DottedSign.
How to Report Suspicious or Malicious Content to DottedSign
If you suspect that a signing request or document involves fraud, phishing, brand impersonation, or misuse of DottedSign services, please report it to us.
See "How to Submit an Abuse Report to DottedSign" for information about what to prepare and how to submit your report.
For general questions about DottedSign, your account, or other service issues, please use the Contact Support form to reach the DottedSign Support team.
Updated