
DocuSign phishing & impersonation
Tech & Clouddocusign.com
4
Impersonation sightings
3
Distinct hosts
2026-07-01
Last detected
2
Official domains
ScanMalware watches every scanned site for signs it is impersonating DocuSign — the brand name in the page title or screenshot text, the brand's logo/favicon on a non-official host, and lookalike domains. A match on a host outside DocuSign's official domains is recorded below.
Official domains
docusign.comdocusign.net
Also known as
—
Detected impersonation sites
| Host | Title | Detected by | Verdict | Date | |
|---|---|---|---|---|---|
| pub-4e9d559e11c54314b7639d20c3d13682.r2.dev | DocuSign Login - Enter your password to sign in | Page text | {"verdict": "Medium Risk", "confidence": 38, "risk level": "medium", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 38, "recommendations": ["⚡ Exercise caution when visiting this website", "🛡️ Ensure your browser and antivirus are up to date", "📋 Website lacks important security headers"], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 50, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Suspicious domain pattern detected"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "rpki validation": {"total": 13, "total risk": 4, "valid count": 11, "invalid count": 0, "not found count": 2}, "network security": {"score": 60, "issues": ["No security headers detected"], "mixed content": false, "secure requests": 1, "security headers": {"detected": false}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 15, "issues": ["Excessive redirects (7)", "Excessive cross-domain redirects (5)"], "total redirects": 7, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 5, "compromised wordpress detected": false}, "domain age scoring": {"penalty": 5, "rdap data": {"domain": "r2.dev", "age days": 1408, "category": "ESTABLISHED", "registrar": "CloudFlare, Inc.", "registration date": "2022-08-23T14:38:38.654000+00:00"}, "has login forms": true, "is hosting subdomain": true}}, "threat categories": [], "security indicators": {"negative": ["No security headers detected", "Excessive redirects (7)", "Excessive cross-domain redirects (5)", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (pub-4e9d559e11c54314b7639d20c3d13682.r2.dev)"], "positive": ["Server IPs have valid RPKI ROA coverage", "HTTPS encryption used", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-01 | View scan → |
| useasoffer.com | e-sign | Page text | {"verdict": "Low Risk", "confidence": 71, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 29, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (useasoffer.com)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 55, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Unusually long URL"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 1, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 40, "issues": ["Excessive redirects (16)"], "total redirects": 16, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["Excessive redirects (16)", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (useasoffer.com)"], "positive": ["HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-01 | View scan → |
| useasoffer.com | e-sign | Page text | {"verdict": "Low Risk", "confidence": 71, "risk level": "low", "risk factors": ["Suspicious URL Patterns", "Brand Impersonation (Docusign)"], "overall score": 29, "recommendations": [], "detailed analysis": {"html forms": {"score": 10, "issues": ["⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (useasoffer.com)"], "password fields": 0, "impersonated brand": "Docusign", "brand mismatch detected": true, "impersonated brand slug": "docusign", "disguised password fields": 0, "brand impersonation detected": true}, "url analysis": {"score": 55, "issues": [], "positive signals": ["HTTPS encryption used"], "suspicious patterns": ["Unusually long URL"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 1, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "phishing signals": {"score": 100, "issues": [], "details": {"matched brand": null, "signals detected": [], "is legitimate domain": false}, "warnings": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 40, "issues": ["Excessive redirects (16)"], "total redirects": 16, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["Excessive redirects (16)", "⚠️ CRITICAL: Brand impersonation detected - Docusign branding on non-official domain (useasoffer.com)"], "positive": ["HTTPS encryption used", "Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2026-07-01 | View scan → |
| pub-5de0eeee09ff443eac563eb154d4aa6c.r2.dev | DocuSign Share File | Logo / favicon | {"verdict": "Low Risk", "confidence": 67, "risk level": "low", "risk factors": ["Suspicious URL Patterns"], "overall score": 33, "recommendations": [], "detailed analysis": {"html forms": {"score": 50, "issues": [], "impersonated brand": null, "brand mismatch detected": false, "disguised password fields": 0, "brand impersonation detected": false}, "url analysis": {"score": 10, "issues": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive signals": [], "suspicious patterns": ["Blob URL used to hide phishing content"]}, "safe browsing": {"score": 100, "issues": [], "threats": [], "positive signals": ["No Google Safe Browsing threats detected"]}, "clone detection": {"score": 100, "issues": [], "warnings": [], "positive signals": ["No visual similarity to known brand sites"]}, "network security": {"score": 65, "issues": [], "mixed content": false, "secure requests": 18, "security headers": {"detected": true}, "insecure requests": 0, "certificate issues": []}, "technology risks": {"score": 50, "issues": [], "security technologies": [], "vulnerable technologies": []}, "redirect analysis": {"score": 50, "issues": [], "total redirects": 0, "blob url detected": false, "protocol downgrades": 0, "suspicious patterns": 0, "cross domain redirects": 0, "compromised wordpress detected": false}}, "threat categories": [], "security indicators": {"negative": ["⚠️ CRITICAL: Blob URL detected as final destination (common phishing technique)"], "positive": ["Good network security practices", "No Google Safe Browsing threats detected", "No visual similarity to known brand sites"], "warnings": []}} | 2025-12-05 | View scan → |