How does Docusign phishing work? Cybercriminals are not spoofing fake Docusign emails, but instead registering real accounts with the company, and using its APIs to send out legitimate envelopes spoofing popular brands. Regular phishing emails spoofing the Docusign brand and taking the user to phishing login pages. Things workers should be taught to look out for include:Destination URLs: hover over any links/buttons in Docusign emails to check the destination URLs are legitimate. Attachments: there should be no attachments in an initial Docusign email.