What Should I Do If I Receive a Suspicious Signing Request?

If you receive a signing request you were not expecting, or the document is not what you expected, do not sign it immediately. First, check who sent it, what you are being asked to sign, and where the email came from.

Even if the signing request was sent through DottedSign, you should still make sure you recognize the sender and that the document is what you expected. This article explains what to check and what to do if a signing request looks suspicious.

 

 

What to Check When You Receive a Signing Request

When it’s your turn to sign, DottedSign sends a signing request to your inbox. The email shows the sender’s name and email address, the document name, and a “View & Sign” button. Before proceeding, check the following:

For the complete list of official domains, see the DottedSign Security Policy.

Note: Even if the email comes from an official DottedSign domain, make sure the sender and the document content match what you were expecting.

 

What to Do If a Signing Request Looks Suspicious

If you do not recognize the sender, were not expecting the document, or the document does not match what you expected, do not click links in the email, download attachments, or continue signing.

If you know the sender, contact them through a method you normally use and confirm that they sent the signing request and that the document is correct. Do not rely only on contact details provided in the email or document.

 

If You Have Not Clicked Any Suspicious Links

  1. Do not click the signing link or any other suspicious links in the email.
  2. Do not download unfamiliar attachments or files from the email or document.
  3. Do not enter your password, personal information, or other sensitive information on an unfamiliar page.
  4. If you confirm that the content involves fraud, malicious content, or misuse of DottedSign services, follow the instructions below to report it to DottedSign.

 

If You Have Already Clicked a Suspicious Link

If you clicked a suspicious link in the email, check your email account and device for unusual activity as soon as possible, and change your email password.

If you entered your login credentials on a suspicious page, check recent activity across accounts or devices that use those credentials and change the affected passwords. We also recommend changing your passwords regularly to reduce potential security risks.

If you believe the signing request involves fraud, malicious content, or misuse of DottedSign services, follow the instructions below to report it to DottedSign.

 

How to Report Suspicious or Malicious Content to DottedSign

If you suspect that a signing request or document involves fraud, phishing, brand impersonation, or misuse of DottedSign services, please report it to us.

See "How to Submit an Abuse Report to DottedSign" for information about what to prepare and how to submit your report.

For general questions about DottedSign, your account, or other service issues, please use the Contact Support form to reach the DottedSign Support team.

 

Updated