SignITLog inRequest access

Trust & safety

Recognising fake signature requests.

Attackers imitate e-signature emails to steal passwords, payment details, or to install malware. Here is how to tell a real SignIT request from a fake, and how to report abuse.

Warning signs of a fake request

  • It asks you to enter your email password or a one-time code to "view" a document. No legitimate signing service needs this.
  • It asks for bank, card, or payment details to open or sign.
  • It pressures you to act urgently, or threatens consequences.
  • The link points somewhere other than yousignit.org (watch for look-alike domains and misspellings), or is not HTTPS.
  • It asks you to download and run an attachment or program to view the document.
  • The sender or document details are vague or missing.

The only valid SignIT web addresses

  • yousignit.org and www.yousignit.org — the public site.
  • app.yousignit.org — the application (documented subdomain).

Valid SignIT sender email addresses will be listed here only once our email routing is operational and verified. Until then, treat any email claiming to be from a SignIT address with extra caution and verify via the checklist above.

Report abuse

Forward a suspicious message or describe it on our contact page (choose "Security / abuse"). Do not enter any credentials first. SignIT is an independent private-alpha product, not affiliated with any other e-signature company.