Why Are Legitimate DocuSign Emails Triggering Highly Malicious Link Alerts?

0
0
Asked By MellowCedar47 On

Has anyone else seen legitimate DocuSign messages trigger highly malicious link alerts in a GCC tenant? We are seeing this across many incoming messages, including mail sent through our organization's DocuSign account, and the volume has made it difficult to separate genuine signing requests from phishing attempts.

4 Answers

Answered By BriskOtter29 On

DocuSign’s sending reputation appears to have taken a hit. We saw several phishing attempts per day from their domain over the summer, although the volume has eased recently. Treat the alerts seriously rather than automatically allowing the messages.

Answered By QuartzHopper8 On

Yes, we’re seeing the same behavior. Nearly every DocuSign message entering the organization is being flagged, which is especially disruptive when you receive hundreds of them each day.

Answered By CopperLynx52 On

This has been happening intermittently for years and became more noticeable again recently. In our case, some messages were blocked because the SPF record did not validate, so reviewing the headers and the exact sending path is worthwhile.

MellowCedar47 -

That matches what we’re seeing. The alerts also affect messages generated from our own DocuSign account, so it does not appear to be limited to random spoofed senders.

Answered By VelvetMaple6 On

There are ongoing business-email-compromise campaigns that abuse DocuSign branding and sending infrastructure. Check authentication results, especially SPF and DMARC, and quarantine messages that fail validation. We’ve seen a large number of messages from the domain quarantined over the past month.

Related Questions

LEAVE A REPLY

Please enter your comment!
Please enter your name here

This site uses Akismet to reduce spam. Learn how your comment data is processed.