Signature requests are close to a perfect phishing disguise. They arrive unexpectedly, they come from an outside party, they ask you to click a link and log in, and they carry mild urgency. That's also an exact description of a legitimate request, which is why these scams work on careful people.
The short version: you often cannot tell a real request from a fake one by inspecting the email. The reliable defence isn't better inspection, it's changing where you open documents from.
Key takeaways
Never sign in through a link in an email. Go to the platform directly and check your pending documents there.
Attackers use real e-signature platforms. Those emails pass every authentication check because they're genuine.
A document arriving through a trusted platform is not automatically safe. Check who sent it and whether you expected it.
QR codes in emails and documents move the attack to your phone, where checks are hardest.
Verify anything involving payment details or credentials by phone, using a number you already have.
If you entered credentials, revoking active sessions matters as much as changing the password.
Why signature requests make such good bait
Phishing works by borrowing trust. E-signature notifications come with three kinds of trust built in: a recognisable brand, a plausible reason to act, and a normal request to log in.
Add the fact that most people can't say exactly what a legitimate request from a given platform looks like — because they receive maybe a few a month, from several different platforms — and the attacker doesn't need a perfect forgery. They need something close enough to pass a three-second glance.
The three attack patterns
1. The lookalike (the classic)
A forged email imitating a well-known platform, linking to a fake login page that captures your credentials. This is the one most security training covers, and the one most likely to be caught by email filters.
What gives it away: a sender domain that isn't the real one, a link that doesn't lead to the platform's real domain, missing document details, generic greetings, and pressure language.
2. Platform abuse (the one that beats your filters)
An attacker creates a free or trial account on a real e-signature platform and sends you a genuine envelope through it. The document itself contains a malicious link, an invoice with the attacker's bank details, or a QR code.
This email is real. It comes from the platform's real servers, passes SPF, DKIM and DMARC, carries the correct branding, and survives every technical check your IT team has configured. No amount of sender inspection will catch it.
What gives it away: you don't recognise the sender name or company; the document is vague ("Review document", "Invoice 4471") with no context; the actual instruction is to click a link inside the document rather than to sign it; or a genuine-looking invoice has payment details that differ from what you have on file.
3. QR codes
A QR code in the email or document moves you onto your phone, which typically sits outside your company's email filtering and URL protection, and where it's much harder to inspect a destination before you land there. A "scan to sign" instruction should be treated as suspicious by default. A legitimate signing flow works in a browser on the device you're already using.
How to check a request
Check whether you were expecting it
This catches more attacks than any technical check. Does the sender's name mean anything to you? Is there a deal, a hire or a renewal this could plausibly relate to? An unexpected document from an unfamiliar name is suspicious even when everything else looks perfect.
Check the sender address, with limits
Look at the full address, not the display name, which can be set to anything. Watch for character swaps (rn for m, 0 for o), extra words, and domains that put the brand in the subdomain rather than the domain, such as nevtan-sign.security-portal.example.com.
Be aware of the limit: in a platform-abuse attack, the sender address is genuine. Passing this check means less than failing it does.
Check links, and know when hovering fails
Hovering to preview a URL still helps when it works. Two situations where it doesn't:
Safe-link rewriting. If your organisation uses a security product that rewrites URLs, every link will show that vendor's domain on hover, telling you nothing about the destination.
Mobile. Long-pressing works, but the preview is truncated and easy to misread, and phones are where people are most rushed.
This is why the "go to the platform directly" habit matters more than link inspection. It works regardless of how sophisticated the email is.
Check what the document actually asks you to do
A real signing request asks you to sign. If opening the document leads to another link, a login prompt for an unrelated service, or a request to "enable content," something is wrong. Legitimate requests also carry context: the sender's name, the document's title, and usually a message explaining what it is.
Verify out of band for anything financial
For payment details, bank-account changes, credential requests or anything unusual from a known contact, call the person using a number you already have. Not the number in the email. This single habit defeats most business email compromise, where a real, compromised account sends the request. Protecting your company from business email compromise covers the wider pattern.
The one habit worth building
Don't sign in through email links. Open a new tab, go to the platform directly, and check your pending documents there.
If a request is real, it's waiting for you. If nothing is there, you've learned what you needed to know without spending any effort on analysis.
This works against all three attack patterns, doesn't depend on your judgement under time pressure, and survives phishing that's better than anything you've seen before. It's worth teaching as a rule rather than a tip.
A realistic scenario
The following is a composite illustrating the pattern, not a specific incident.
An account manager receives a signature request from a well-known e-signature platform. The subject references a contract renewal. The sender name matches a client contact she works with, though the email address is one she hasn't seen before.
The email is genuine. An attacker registered a trial account on the platform using a display name matching her client. Every authentication check passes, so nothing is flagged.
She opens the document. Rather than a contract with signature fields, it contains a line of text and a link: "Click here to view the full agreement." The link leads to a credential-harvesting page imitating her company's single sign-on.
Two things would have stopped it. First, the document asked her to click a link rather than to sign, which a real signing request never does. Second, checking with the client through a known channel would have taken a minute.
Note what none of the standard advice would have caught: the sender domain was legitimate, the branding was correct, and the email passed every filter.
If you clicked
Speed matters more than thoroughness. In order:
Tell IT or your security contact immediately. Not after you've tried to fix it yourself. Early reporting is what limits the damage, and nobody should feel they'll be blamed for it.
If you entered credentials, change the password from a different device and revoke all active sessions on that account. A password change alone doesn't help if the attacker already holds a valid session cookie.
Enable multi-factor authentication if it isn't already on. Setting up two-factor authentication walks through it.
Change the password anywhere you reused it. This is the main reason reused passwords are dangerous.
Check for changes the attacker may have made: new mail forwarding rules, new authorised devices, changed recovery addresses. Forwarding rules are the usual persistence trick and are easy to miss.
Watch for follow-on attacks on colleagues and clients. A compromised account is usually a staging point rather than the goal.
What organisations can do
Authenticate your own domain. SPF, DKIM and a DMARC policy set to quarantine or reject stop attackers sending mail that appears to come from your domain. This protects your clients from being phished in your name, which is its own reputational and liability problem. See how DMARC records work and email spoofing explained.
Standardise on one platform. If everyone knows the company signs documents in one place, a request from anywhere else is immediately odd. Mixed tooling removes that signal entirely.
Route signing through defined workflows. When contracts originate from your CRM or HR system rather than from ad-hoc emails, unexpected requests stand out. Common signing workflows covers the usual patterns.
Make reporting easy and blameless. The most expensive incidents are the ones people hide for a day.
Train on the realistic version. Training built around obvious fakes with spelling errors leaves people confident about threats that no longer resemble what they'll actually receive. Include platform abuse and QR codes. The email security guidance for small businesses is a reasonable starting point.
What to look for in a platform
No platform prevents phishing that imitates it, so evaluate what happens when something goes wrong and how well you can verify what's real:
Multi-factor authentication, ideally with support for phishing-resistant methods such as passkeys or hardware keys.
A complete audit trail recording who signed, when, from where, and how identity was confirmed. See how e-signature security and audit trails work.
Signer identity verification for high-value documents — an SMS code or ID check raises the bar considerably.
A dashboard showing pending documents, so people can verify requests without touching email links.
Admin visibility and access controls, so you can see what's outstanding across the organisation.
Documented security practices. NevTan Sign's security page sets out how documents are protected.
How to choose an e-signature tool covers the broader evaluation.
Common mistakes
Treating a platform-sent request as automatically safe. Real platforms deliver malicious documents daily. Check the sender and whether you expected it.
Relying on hovering alone. It fails with safe-link rewriting and on mobile.
Trusting the display name. It's freely editable and matches a real colleague in most successful attacks.
Scanning QR codes from email. It moves you to the least protected device you own.
Reusing passwords. One phishing success becomes many.
Changing the password but not revoking sessions. The attacker keeps their access.
Delaying the report. Hours matter.
FAQ
What is a fake e-signature request email?
A phishing message imitating a signature notification, designed to capture your credentials or deliver malware. Some are forgeries of a platform's emails; others are genuine emails sent through a real platform by an attacker with an account on it.
Can a phishing email come from a real e-signature platform?
Yes, and this is now common. Attackers register accounts and send genuine envelopes containing malicious links or fraudulent invoices. These pass all authentication checks because they really do come from the platform.
How do I tell if a request is legitimate?
Ask whether you expected it and whether you recognise the sender. Then open the platform directly, without using the email link, and see if the document is waiting for you. Inspecting the email alone is not reliable.
Is hovering over links still useful?
Partly. It helps when links aren't rewritten by a security product and when you're on a desktop. It's unreliable on mobile and useless when your organisation rewrites URLs. Going to the platform directly works in every case.
What if I already clicked?
Report it to IT immediately, then change the password from a different device and revoke active sessions. Enable multi-factor authentication, update any reused passwords, and check for new forwarding rules on your mailbox.
Can a phishing email come from someone I know?
Yes. Compromised accounts send real emails from real addresses. For anything involving payments or credentials, verify by phone using a number you already have.
Are small businesses targeted?
Yes, often more than large ones, because they typically have less filtering and less training. The basic defences — MFA, domain authentication and a direct-login habit — are inexpensive and effective.
What are the legal consequences of a breach?
A breach involving personal data can trigger notification duties and penalties under regimes such as GDPR, along with contractual liability to affected clients. Requirements vary by jurisdiction and industry, so take specific advice. [LEGAL REVIEW]
Related reading
CTA
Phishing that imitates signing requests works best where signing is ad hoc. When documents flow from your CRM, HR and legal systems through one platform with multi-factor authentication and a full audit trail, an unexpected request stands out immediately. See how NevTan Sign handles document security, or get started.
