{"success":true,"data":{"id":"docusign-signature-cross-domain","label":"Fake DocuSign \"document waiting for signature\" or \"envelope expires today\" notice sent from a non-DocuSign domain — credential-harvest cross-domain phish; signature requests are a low-suspicion lure that masks fake login portals. Real DocuSign mail originates from docusign.net / docusign.com only.","description":"Fake DocuSign \"document waiting for signature\", \"envelope expires today\", or \"completed document available\" notice sent from a non-DocuSign sending domain (From / Reply-To / link domains do not align with docusign.net / docusign.com / docusign.com.au) directing the recipient to a \"review and sign\" link — credential-harvest cross-domain phish that masquerades as a routine business signature request. Real DocuSign communications originate exclusively from docusign.net or docusign.com with DMARC-aligned signing; \"review document\" links always terminate at docusign.net, never at third-party domains. Signature-request lures bypass normal suspicion because employees expect contracts and NDAs via DocuSign — the cross-domain mismatch is the defining tell. Distinct from generic e-signature-phish — this targets the DocuSign brand / envelope-waiting / cross-domain From-link mismatch pretext. Detection: DocuSign brand vocabulary (document waiting for signature, envelope expires, review and sign) + sender or link domain ≠ docusign.net / docusign.com + no DMARC alignment. Trash score: +5. Source: GC1-R31; APWG DocuSign phishing report 2025; DocuSign anti-phishing guidance; FBI IC3 e-signature impersonation alert.","tier":"warning","category":"other","isThin":false}}