No specific threat detected
Legitimate DocuSign subdomain displaying an expired signing link on a 27-year-old domain with clean scans.
Is na3.docusign.net legit or a scam?
Legitimate DocuSign subdomain displaying an expired signing link on a 27-year-old domain with clean scans.
This is a legitimate DocuSign subdomain showing an expired link notice. The domain is 27 years old, carries valid EV SSL, and no antivirus engine flagged it.
Analysis Summary
Website Preview

Automated page render — captured in a safe sandbox. What an ordinary visitor would see when loading the site.
Visual analysis
We capture a fresh screenshot of the live page and ask a vision model to look for scam visual patterns — fake trust badges, countdown timers, overlay pop-ups, and visual clones of legitimate brands.
No scam visual patterns detected
The screenshot shows a standard, functional error page for an expired DocuSign link, which appears to be a legitimate interface.
What our vision model saw
3 signalsPage displays a standard DocuSign 'link expired' notification
Visual design and branding are consistent with legitimate DocuSign interfaces
No suspicious overlays, countdowns, or deceptive input forms present
Intelligence
The URL points to na3.docusign.net, a subdomain DocuSign uses for its eSignature platform. The page shows a standard expired-link message with matching official branding and no login forms or data-collection fields. The domain itself was registered in 1999, uses DigiCert EV SSL, and returns zero detections across 92 antivirus engines. Two scam reports mention phishing emails that impersonate DocuSign, but they do not flag the actual docusign.net infrastructure. The combination of long-established ownership, clean technical signals, and an expected error page confirms this is the real service rather than a fake.
Web Research Findings
Independent findings for na3.docusign.net, including public complaints, named review sources, registration records, and look-alike-domain evidence. A missing result is shown as unverified, never converted into a clean bill of health.
- na3.docusign.net is a legitimate subdomain operated by DocuSign for its electronic signature services.
- The domain is frequently targeted by phishing campaigns that impersonate DocuSign to steal credentials or sensitive information.
- Legitimate DocuSign emails and links will always originate from docusign.net or docusign.com.
- Users are advised to hover over links before clicking to verify they point to official docusign.net or docusign.com domains.
- DocuSign provides a verification service (verify@docusign.com) for users to check the authenticity of suspicious emails.
- CSULB Phish Bowlopen
"With the increasing use of DocuSign as the campus's eSignature software solution, employees and students may become more vulnerable to phishing attempts that are posing as DocuSign forms."
- The Hartfordopen
"Recently, DocuSign has warned its customers about potential phishing campaigns involving compromised emails that appear to be sent from their domain."
DocuSign, Inc. is a publicly traded company (NASDAQ: DOCU) headquartered in San Francisco, California.
Public sources note that attackers send phishing emails pretending to be DocuSign. The advisories from CSULB and The Hartford explicitly state that real DocuSign links originate from docusign.net or docusign.com and recommend hovering over links to verify the domain. No scam reports or complaints target the actual na3.docusign.net subdomain.
Domain Timeline
- Jun 14, 1999Domain registered
First appeared in WHOIS records — 27 years old today.
- Jul 22, 2026Latest security review — Reviewed as safe
This scan re-ran every check and found no active threat signals.
na3.docusign.net has operated for years with no threat signals in this review — a long, stable track record, though it is never a guarantee on its own.
Threat Detection
Antivirus Engines
Security Scans
Checked against the major public blocklists used by browsers and security tools — no hits.
Reputation Sources
How this domain rates across independent threat-intelligence and blocklist providers.
Technical Details
domain · encryption · redirects · server reputation · referencedThe plumbing behind the site — who registered it, how it’s encrypted, where it’s hosted, and where it links out. A valid certificate or a calm server doesn’t mean the business is honest — scam sites pass these checks too. Use this to corroborate the verdict, not to overturn it.
Contact Verification
We fetched the page and looked for real-world contact details. Legitimate businesses almost always publish an email on their own domain, a phone number, and a postal address. Scam shops usually don't.
- No contact email found anywhere on the page.
- No phone number listed on the page.
- No postal address visible on the page.
Domain & Encryption
Redirect Chain
- 1302https://na3.docusign.net/Signing/EmailStart.aspx?a=2a16c30b-4d00-88fd-8183-7c243c89de61&etti=25&acct=a251f830-3c3d-4551-a231-3db36da0a1af&er=3d5a791f-591d-803f-8146-a9f7bca51382&ensd=OlmiHSbJ0eI9ZkG%252fXULDavsIaD2SbXVCWOhmmcNmXJ32bKPoES0njN%252f0w79JW5yXJNBKauuQv3fha69jiDSrF7BtJmWv3b3g1ma1qtVmUcBPi%252bM2QRAbqg7EaL9TWWHXYPO1nY%252b%252fuE3V3cvhMAbPUwHffsNrFmNK%252bmBsyarz5pxlDzgiLUhBhZrAtK1y3rrB&data=05%7C02%7Cyancheen.wong%40samwoh.com%7C10f4f7db49734950701f08dee7b5aadb%7C841af22f54054a67ad10ab74fc5592e8%7C1%7C0%7C639202964608919109%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Z1yHaHxep8j1eA2FCCcM28EVSRi4t6S+9LXunre8Imo%3D&reserved=0
- 2302https://na3.docusign.net/Signing/EmailStart.aspx?a=2a16c30b-4d00-88fd-8183-7c243c89de61&etti=25&acct=a251f830-3c3d-4551-a231-3db36da0a1af&er=3d5a791f-591d-803f-8146-a9f7bca51382&ensd=OlmiHSbJ0eI9ZkG%252fXULDavsIaD2SbXVCWOhmmcNmXJ32bKPoES0njN%252f0w79JW5yXJNBKauuQv3fha69jiDSrF7BtJmWv3b3g1ma1qtVmUcBPi%252bM2QRAbqg7EaL9TWWHXYPO1nY%252b%252fuE3V3cvhMAbPUwHffsNrFmNK%252bmBsyarz5pxlDzgiLUhBhZrAtK1y3rrB&data=05%7C02%7Cyancheen.wong%40samwoh.com%7C10f4f7db49734950701f08dee7b5aadb%7C841af22f54054a67ad10ab74fc5592e8%7C1%7C0%7C639202964608919109%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Z1yHaHxep8j1eA2FCCcM28EVSRi4t6S+9LXunre8Imo%3D&reserved=0&AspxAutoDetectCookieSupport=1
- 3200https://na3.docusign.net/Signing/(X(1)S(jdwlujti3rsnkssfwwbqgoza))/EmailStart.aspx?a=2a16c30b-4d00-88fd-8183-7c243c89de61&etti=25&acct=a251f830-3c3d-4551-a231-3db36da0a1af&er=3d5a791f-591d-803f-8146-a9f7bca51382&ensd=OlmiHSbJ0eI9ZkG%252fXULDavsIaD2SbXVCWOhmmcNmXJ32bKPoES0njN%252f0w79JW5yXJNBKauuQv3fha69jiDSrF7BtJmWv3b3g1ma1qtVmUcBPi%252bM2QRAbqg7EaL9TWWHXYPO1nY%252b%252fuE3V3cvhMAbPUwHffsNrFmNK%252bmBsyarz5pxlDzgiLUhBhZrAtK1y3rrB&data=05%7C02%7Cyancheen.wong%40samwoh.com%7C10f4f7db49734950701f08dee7b5aadb%7C841af22f54054a67ad10ab74fc5592e8%7C1%7C0%7C639202964608919109%7CUnknown%7CTWFpbGZsb3d8eyJFbXB0eU1hcGkiOnRydWUsIlYiOiIwLjAuMDAwMCIsIlAiOiJXaW4zMiIsIkFOIjoiTWFpbCIsIldUIjoyfQ%3D%3D%7C0%7C%7C%7C&sdata=Z1yHaHxep8j1eA2FCCcM28EVSRi4t6S+9LXunre8Imo%3D&reserved=0&AspxAutoDetectCookieSupport=1
Server Reputation
Referenced Domains
Outbound domains this page links to or loads resources from. Each links to its own security scan.
What to do
Still, stay alert
No major threat indicators — but a clean scan does not guarantee every page is safe, and phishing emails routinely spoof real domains.
- Double-check the exact URL in your address bar
Confirm you are actually on na3.docusign.net and not a lookalike like n-a3.docusign.net.com or an IDN homoglyph.
- Use a password manager
Password managers only auto-fill on the exact domain they were saved for — they refuse to fill lookalike domains, which is the single best phishing defence.
- OpenDiscuss this site on the forum
If you have first-hand experience with this site — good or bad — share it with the MalwareTips community.
Final Verdict
This is a legitimate DocuSign subdomain showing an expired link notice. The domain is 27 years old, carries valid EV SSL, and no antivirus engine flagged it.
Safety FAQ
Common questions, answered directly from the scan data above — so the answers always reflect the latest verdict on this page.
- Our automated security review found no threat indicators on na3.docusign.net, so it appears legitimate. All 92 antivirus engines we queried report it clean, and the domain is 27.1 years old, registered on June 14, 1999 — established domains are far less likely to be scams. Even so, always double-check the exact address in your browser, because phishing emails routinely spoof real, trusted domains like this one.
- na3.docusign.net passed our automated checks with a trust score of 94/100. No antivirus engines or major blacklists flagged it at the time of the last scan, and its signals line up with an established, legitimate site. Treat any unexpected login prompt or payment request on it with the same caution you would anywhere.
- Yes — and this is worth understanding. Even trustworthy domains get spoofed in phishing emails (a fake message that only looks like it's from na3.docusign.net), and legitimate sites are occasionally compromised on specific pages. A clean verdict means the site itself checks out today; it does not mean every email or link claiming to be from na3.docusign.net is genuine. Always reach the site by typing the address yourself rather than clicking links in unexpected messages.
- No — all 92 antivirus and blocklist engines in our malware network currently report na3.docusign.net as clean. That's a good sign, though antivirus coverage is only one of the many signals we weigh, and brand-new scam sites can appear clean before vendors catch up.
- No — na3.docusign.net is not currently on the major browser blocklist feeds that Chrome, Safari, Firefox, and Edge rely on. Note that blocklists can lag behind brand-new scam domains, so "not listed" is reassuring but not a guarantee on its own.
- na3.docusign.net is 27.1 years old, registered on June 14, 1999 through MarkMonitor Inc.. A multi-year registration history is one of the stronger signals against a scam, though it's never a guarantee on its own — established domains can still be misused.
- Yes — na3.docusign.net presents a valid TLSv1.3 certificate issued by DigiCert Inc · DigiCert EV RSA CA G2, valid for another 188 days. Important caveat: SSL only encrypts the connection between you and the site — it does not verify who runs it. Almost all scam sites now have valid SSL too, so a padlock alone never means "safe".
- na3.docusign.net resolves to an IP operated by Microsoft Corporation in US (Data Center/Web Hosting/Transit). Hosting location alone doesn't make a site good or bad — but hosting that doesn't match a brand's claimed country, or that sits on networks known for abuse, is one of the many signals we weigh alongside the verdict above.
- This report is a record of the scan run on July 22, 2026, and the verdict reflects that point in time. Scam sites change fast — they can go live, get flagged, or vanish within days — so if you believe something about na3.docusign.net has changed, MalwareTips staff can run a fresh scan that re-checks every signal from scratch and republishes an updated verdict.
User reviews & comments(0)
Share your experience — "Lost $200 on a fake checkout" is more useful than "Scam". Your review helps others avoid traps.