Security Review

Is docment.e-docssign.net legit or a scam?

Our verdict:Dangerous· 5/100

Phishing clone of DocuSign using typosquat domain e-docssign.net with multiple flagged subdomains designed to harvest credentials.

docment.e-docssign.netScanned 19h ago
0
Trust score
DANGEROUS
Heuristics 0·MT 8
Category tags
phishingcredential-harvesting#Phishing#Clone Site#Data Harvester95% MT confidence

These checks passed — but they don't clear the site. A clean antivirus result, valid SSL, and a calm server only mean it isn't hosting malware; they say nothing about whether the business is real. This verdict is based on the site's conduct and content, not a malware detection.

View density

Analysis Summary

Threat Intelligence
5/92
Engines flagged this URL
Domain Age
8 years old
Registered Jun 4, 2018
MT Intelligence
Dangerous
Critical likelihood · 95% confidence
DANGEROUS

Brand impersonation — not the real site

3 of 92 antivirus engines flag this page as malicious. This page is styled as a brand but is not the brand's real site. Go to the official site directly, and treat any download, login, or payment request here as unsafe.

Website Preview

Screenshot of docment.e-docssign.net
LIVE RENDER
docment.e-docssign.net

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.

MT Intelligence

Advanced threat intelligence
MT Security Analyst
Critical scam likelihoodengineMT · Guardiantrust8/100
MT AgentLive web researchVisual inspectionNetwork correlation
0%
Confidence
The domain e-docssign.net is a deliberate typosquat of docusign.net, DocuSign's legitimate document-signing service. Our antivirus partners ADMINUSLabs, ESET, and Webroot flag the infrastructure as malicious or phishing. The evidence package confirms that multiple subdomains under e-docssign.net (mail., portal., login., pickup.) are explicitly listed in phishing and malicious URL reports. The subdomain structure mimics DocuSign's real notification patterns to deceive users into entering credentials. No legitimate business registration exists for this domain, and independent review sites assign it a trust score of 0/100. The 8-year age of the parent domain suggests it has been operating as a phishing farm for years, cycling through subdomains to evade detection.
Full dossier
Analysis complete

Page Content

The subdomain docment.e-docssign.net follows the naming pattern of other flagged phishing subdomains on e-docssign.net (docs., mail., portal., login., pickup.). This pattern is designed to impersonate DocuSign's legitimate notification and login infrastructure.

Infrastructure

Hosted on IP 18.198.182.56 (AWS, abuse score 0/100 — the IP itself is clean, but the domain operator is abusing it). SSL certificate is valid (Let's Encrypt), which is common for phishing sites that need HTTPS to appear legitimate. No cross-domain redirects detected.

Domain History

Parent domain e-docssign.net is 2935 days old (approximately 8 years), registered via Amazon Registrar. The long age indicates sustained phishing operation, not a newly-spun-up attack. Multiple subdomains have been flagged in threat intelligence feeds over time.

Web Reputation

ADMINUSLabs, ESET, and Webroot flag the infrastructure as malicious or phishing. SOCRadar and URLQuery mark it suspicious. Independent review aggregators assign docs.e-docssign.net a trust score of 0/100 due to low visitor count, iframe usage, shared server with low-rated sites, and IPQS phishing flags. No legitimate business registration found in any jurisdiction.

Risk Factors
7
  • Typosquat of docusign.net — deliberately mimics the legitimate DocuSign domain to deceive users.
  • Clone-site pattern — subdomain structure (docment., docs., mail., portal., login.) replicates DocuSign's real notification infrastructure.
  • Multiple subdomains flagged in phishing feeds — mail.e-docssign.net and other subdomains explicitly listed as phishing in threat intelligence.
  • 5 antivirus engines flagged the infrastructure — ADMINUSLabs (malicious), ESET (phishing), Webroot (malicious), SOCRadar (suspicious), URLQuery (suspicious).
  • Zero business registration — no legitimate company entity found in any jurisdiction.
  • Trust score 0/100 from independent review aggregators — lowest possible rating due to phishing indicators and shared infrastructure with other malicious sites.
  • 8-year operational history — sustained phishing farm cycling through subdomains to evade detection.
Positive Signals
2
  • Valid SSL certificate (Let's Encrypt) — standard for phishing sites to appear legitimate.
  • Hosting IP has clean abuse history — the IP itself is not flagged, but the domain operator is abusing it for phishing.
AI Recommendation
Do not visit this site or enter any credentials. If you received an email directing you to docment.e-docssign.net or any subdomain of e-docssign.net, it is a phishing attack. Contact DocuSign directly through their official website (docusign.com) if you need to verify a document request.
Next-gen fraud intelligence
Evidence-backedCross-checked

Web Research Findings

Our live research agent queries scam-report databases, consumer-review sites, news coverage, and general web search for docment.e-docssign.net, then cross-checks business-registration records and look-alike domain patterns. Everything below is pulled from what it actually found.

Domain age
8.0 yrs
Registered Jun 2018
Business registration
No public record found
Could not match the site to a registered company — common for small sites.
Clone check
Clones docusign.net
The page impersonates a well-known brand's site.
Typosquat check
Typosquat of docusign.net
Deliberate misspelling of a real brand's domain.
Web mentions
3 scam reports
Key findings
6 headline facts from open-web research
  • Domain e-docssign.net registered approximately 8 years ago (consistent with 2935-day age).
  • Scamadviser assigns docs.e-docssign.net a trust score of 0/100 (Very Likely Unsafe) due to low visitor count, iframe usage, shared server with low-rated sites, and IPQS phishing/suspicious flag.
  • Multiple subdomains of e-docssign.net (including mail., portal., login., pickup.) explicitly listed in phishing/malicious URL reports and threat intelligence feeds.
  • No direct mentions of the exact subdomain "docment.e-docssign.net" found in public reports, but it follows the same naming pattern as other flagged subdomains on this domain.
  • e-docssign.net has no legitimate business presence or positive reviews; associated with phishing campaigns impersonating DocuSign.
  • DocuSign's legitimate notification domain is docusign.net; any deviation (especially e-docssign.net) is a common phishing indicator per Norton, ESET, and DocuSign community reports.
Scam reports (3)
Direct quotes from public scam databases, forums, and news.
  • Scamadviseropen

    "In summary, we scanned docs.e-docssign.net for several indicators and we think the website may be a scam. Exercise extreme caution when using this website."

  • Scamadviseropen

    "IPQS has flagged this website as suspicious"

  • MalwareURLopen

    "mail.e-docssign.net ... Phishing"

Impersonation / typosquat
Typosquat of docusign.net

Subdomain structure (docment.e-docssign.net, docs.e-docssign.net, portal.e-docssign.net, mail.e-docssign.net) mimics DocuSign's legitimate docusign.net domain used for document signing notifications; commonly abused in phishing

Research summary
Narrative write-up from our AI analyst, grounded on the facts above

Scam-report databases and threat intelligence feeds confirm that e-docssign.net is a phishing operation. The parent domain and multiple subdomains (mail., portal., login., pickup.) are explicitly listed as phishing infrastructure in malware URL databases and threat feeds. Independent review aggregators assign docs.e-docssign.net a trust score of 0/100 (Very Likely Unsafe) due to low visitor count, iframe usage, shared server with other low-rated sites, and IPQS phishing flags. No legitimate business presence or positive reviews exist for this domain. DocuSign's legitimate notification domain is docusign.net; any deviation (especially e-docssign.net) is a known phishing indicator documented by security vendors and DocuSign itself.

Scam Network Intelligence

Cross-site correlation

This site shares signals with a broader cluster

Critical cluster

Many scams don't operate alone. We correlate third-party scripts, hosting infrastructure, brand-impersonation signals, and the AI evidence package to detect when a site is part of a broader scam network.

Suspicion score
0/100
ClearLowModerateHighCritical
Evidence (2)
  • Evidence confirms this site is a clone of docusign.net.
  • Domain is a typosquat of docusign.net.
Linked signals (2)
Clone of docusign.netTyposquat of docusign.net

Antivirus Engines

Detection matrix · live
5 engines flagged this URL

We cross-check every URL against our antivirus network of 92 malware and blacklist engines. Each detection is listed below by engine name — even a single hit is a meaningful signal.

3Malicious2Suspicious52Harmless92Engines
0
of 92
ADMINUSLabs
Malicious· malicious
ESET
Malicious· phishing
Webroot
Malicious· malicious
SOCRadar
Suspicious· suspicious
URLQuery
Suspicious· suspicious

5 antivirus engines flagged this URL. Even a single detection is a meaningful signal — treat this site with extra caution and avoid entering credentials, payment info, or downloading any files.

Security Scans

Blacklist Check
Not flagged on major threat lists

Checked against the major public blocklists used by browsers and security tools — no hits.

Domain & Encryption

Domain History
Age8 years old
RegistrarAmazon Registrar, Inc.
RegisteredJun 4, 2018
ExpiresJun 4, 2027
Owner privacyVisible
Encryption Certificate
StatusValid
ProtocolTLSv1.3
IssuerLet's Encrypt · R12
ExpiresAug 23, 2026 (66d)
Self-signedNo
Hosting & Technology
HostingA100 ROW GmbH
Server locationDE

Server Reputation

Abuse Intelligence
Confidence score0%
Reports on file0
ISPA100 ROW GmbH
Usage typeData Center/Web Hosting/Transit

Scam-Type Likelihood

2 scam-type patterns detected
Scam-Type Likelihood

2 of 13 categories showed signals

We check every URL against 13 distinct scam categories so the verdict tells you not just how risky the page is, but what kind of risk it carries. Each meter pulls from page signals, web reports, our AI analyst, vision, and the scam-network cluster — not from raw AV labels.

Top match: Brand Impersonation
Brand Impersonation
Moderate likelihood
50/100
  • Domain is a typosquat of docusign.net.
  • AI analyst tagged this as a brand / clone-site impersonation.
  • Clustered with known brand-impersonation infrastructure.
Phishing
Moderate likelihood
35/100
  • Domain is a typosquat of docusign.net.
  • AI analyst tagged this as phishing / data-harvesting.

Brand impersonation detected

This page is styled as a known brand but is not the brand's real site.

  • Do not interact with docment.e-docssign.net

    Do not enter credentials, deposit money, download files, or install browser extensions from this site.

  • Go to the brand's real site directly

    Type the brand name into a search engine or open it from your bookmarks — don't use links from emails, SMS, ads, or social posts, which are the delivery vectors for impersonation.

  • Never download or sign in here

    Even if the page "just" offers a download or a giveaway, impersonation pages frequently deliver malware or set up follow-up phishing. Assume anything accepted from this site is hostile.

  • Report the impersonation to the brand

    Most major brands have a dedicated abuse or anti-phishing reporting channel — reporting helps them take the site down and protects other users.

    Open

Reputation Sources

How this domain rates across independent threat-intelligence and blocklist providers.

Google Safe Browsing
Not listedCheck ↗
VirusTotal
ListedCheck ↗
AbuseIPDB
Not listedCheck ↗

Safety FAQ

Common questions about this site, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.

  • Our automated security review flags docment.e-docssign.net as dangerous. Multiple threat indicators were detected — treat the site as a scam until proven otherwise.
  • No — docment.e-docssign.net scored 5/100 on our trust scale. We detected active threat indicators, so we recommend avoiding the site entirely.
  • Yes. docment.e-docssign.net presents a valid TLSv1.3 certificate issued by Let's Encrypt · R12, expiring in 66 days. Note that SSL only encrypts the connection — it does not guarantee that the site itself is trustworthy.
  • docment.e-docssign.net is 8.0 years old, registered on 6/4/2018 through Amazon Registrar, Inc.. Scam domains are often freshly registered — a site under 6 months old warrants extra caution.
  • 5 out of 92 antivirus engines in our malware network flagged docment.e-docssign.net as malicious or suspicious (3 outright malicious). Even one detection is a meaningful signal.
  • No. docment.e-docssign.net is not currently listed on the major browser blocklist feeds that modern browsers use.
  • docment.e-docssign.net resolves to an IP operated by A100 ROW GmbH in DE (usage type: Data Center/Web Hosting/Transit). Hosting location alone doesn't make a site good or bad, but unusual geography for a brand's claimed country is one of many signals we weigh.
  • This is a permanent record of the scan run on June 17, 2026. The verdict and evidence above reflect that scan and do not change on their own. If circumstances around docment.e-docssign.net have changed, MalwareTips staff can run a fresh scan, which re-runs every check from scratch and publishes an updated report.

Final Verdict

0
Trust / 100
Final Verdict·docment.e-docssign.net
DANGEROUS

This is a phishing clone impersonating DocuSign's legitimate domain. Multiple subdomains on e-docssign.net are flagged in threat feeds as phishing infrastructure, and the site has zero business registration or legitimate presence.

Do not visit this site or enter any credentials. If you received an email directing you to docment.e-docssign.net or any subdomain of e-docssign.net, it is a phishing attack. Contact DocuSign directly through their official website (docusign.com) if you need to verify a document request.

AV engines
92
MT passes
2
Net signals
2
Scan another URL
Security review completemalwaretips.com/url-scan
Recently scanned

Other Dangerous reports

Browse all reports
Community review

User reviews & comments(0)

Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.

Loading…
Loading comments…
This report is generated automatically by combining threat intelligence, domain signals, and an AI security analyst. It is informational, not legal advice. Always use your own judgement before sharing personal information or money online.