Has anyone else seen legitimate DocuSign messages trigger highly malicious link alerts in a GCC tenant? We are seeing this across many incoming messages, including mail sent through our organization's DocuSign account, and the volume has made it difficult to separate genuine signing requests from phishing attempts.
4 Answers
DocuSign’s sending reputation appears to have taken a hit. We saw several phishing attempts per day from their domain over the summer, although the volume has eased recently. Treat the alerts seriously rather than automatically allowing the messages.
Yes, we’re seeing the same behavior. Nearly every DocuSign message entering the organization is being flagged, which is especially disruptive when you receive hundreds of them each day.
This has been happening intermittently for years and became more noticeable again recently. In our case, some messages were blocked because the SPF record did not validate, so reviewing the headers and the exact sending path is worthwhile.
There are ongoing business-email-compromise campaigns that abuse DocuSign branding and sending infrastructure. Check authentication results, especially SPF and DMARC, and quarantine messages that fail validation. We’ve seen a large number of messages from the domain quarantined over the past month.

That matches what we’re seeing. The alerts also affect messages generated from our own DocuSign account, so it does not appear to be limited to random spoofed senders.