Has anyone else seen legitimate DocuSign messages trigger Microsoft Exchange or email-security alerts for highly malicious links, particularly in GCC environments? This appears to be happening broadly across the tenant rather than with one isolated message or sender.
4 Answers
There have been recurring phishing and business-email-compromise campaigns that abuse DocuSign-related infrastructure, so the service’s sending reputation may be contributing to the detections. Some messages also fail SPF or DMARC checks, which can cause them to be blocked or quarantined.
We’ve had the same issue recently. Unfortunately, many DocuSign links received by users have turned out to be malicious, so it’s difficult to broadly allow the domain without carefully validating authentication results, sender details, and the destination URL.
Yes, we’re seeing this on nearly every DocuSign email entering the organization. We process hundreds of them daily, so the alerts and quarantines add up quickly.
This has been happening intermittently for months, although the frequency seems to vary. One organization reported hundreds of quarantined messages from DocuSign addresses within a 30-day period, while another saw its spam filter block them because the SPF record did not align.

That matches what we’re seeing too—the alert seems to affect messages from our legitimate DocuSign setup, not just random spoofed senders.