The Email That Shouldn’t Have Fooled Anyone (But Almost Did)

Last week, an email landed in a client inbox with the subject line: “Reminder: Complete with Docusign: Outstanding Remittance Advise & Inv. xslx.”

At first glance, it checked every box people are trained to look for:

– It came from an address ending in @docusign.net
– Gmail’s own security panel showed “signed-by: docusign.net
– The connection was flagged as “Standard encryption (TLS)”
– The email design, logo, and “Review Document” button were pixel-perfect DocuSign branding

If you were taught to “check the sender domain” and “look for the lock icon,” this email passes. That’s the problem.

Here’s What DocuSign’s Own Interface Doesn’t Show You Up Front

Buried inside the email body — not in the sender line, not in the security summary Gmail displays by default — was the real origin of the request:

> Account Payables
> quickbooks-notification.intuit.com@fmqlv.com

Read that again. The email genuinely came through DocuSign’s infrastructure. The DKIM signature is real. The TLS encryption is real. Gmail even flagged it “Important according to Google magic” — its own AI decided this looked legitimate enough to prioritize.

But the sender who requested the signature inside that envelope has nothing to do with QuickBooks, Intuit, or the recipient’s actual vendors. It’s a spoofed display name riding on a domain (fmqlv.com) that exists for no reason other than to imitate “Intuit” at a glance.

This is a technique security teams call legitimate-infrastructure abuse (sometimes called “trusted platform phishing”). Scammers don’t need to fake DocuSign’s servers, spoof DKIM, or beat a spam filter — they simply open a free or compromised DocuSign account and send a real envelope through it. Every technical signal your email provider checks comes back clean, because technically, nothing about the delivery is fake. Only the human asking for the signature is fraudulent.

Why This Matters More for CPA Firms and Financial Services

If you’re searching for “is this DocuSign email a scam” or “DocuSign phishing email real or fake,” here’s the short answer: DocuSign itself can be 100% real and the request can still be a scam. The platform is a delivery mechanism, not a verification system for who’s asking you to sign.

This matters most for:

Accounting and CPA firms, where “outstanding remittance” and “invoice” language targets accounts payable staff directly
Any business processing vendor payments, where a convincing fake invoice can result in a wire transfer to a criminal’s account
Employees trained only on the basics — domain checking and padlock icons — who have never been shown a real example like this one

We see this pattern constantly in the security assessments we run for clients across Wisconsin, and it’s a growing category of business email compromise (BEC) that traditional spam filtering alone won’t stop.

How to Actually Validate a DocuSign Request

Don’t rely on the sender domain or the lock icon alone. Here’s the checklist we walk clients through:

1. Open the email body, not just the header. Look for the actual requester’s name and email address inside the message — it’s often several lines below the DocuSign branding, exactly like the “quickbooks-notification.intuit.com@fmqlv.com” example above.
2. Ask: do I have an actual relationship with this sender? If “Account Payables” isn’t a name tied to a real vendor or colleague you work with, stop there.
3. Never click “Review Document” to verify. Instead, contact the supposed sender through a phone number or email address you already have on file — not one provided in the email.
4. Check the security code manually if you’re unsure. Legitimate DocuSign emails include an alternate method: go directly to docusign.com, click “Access Documents,” and enter the security code shown in the email rather than clicking any link.
5. Look at the destination domain in any button link, not just the sender. Hover before you click, every time.
6. Be suspicious of urgency language — “Reminder,” “Outstanding,” “Complete Now” — paired with a financial document. Legitimate vendors don’t typically escalate invoice reminders through e-signature platforms.
7. Report it internally before deleting it. One employee catching this protects the whole organization — but only if there’s a clear process to flag it.

This Is Exactly Why “Check the Sender” Isn’t Enough Training

Most phishing awareness training still teaches people to check for a lock icon, a matching domain, and good grammar. This email had all three. That’s precisely why real-world examples — not generic slideshows — are what actually change behavior.

How P3C Technologies Helps

At P3C Technologies, we’ve been helping businesses in West Bend and across the region navigate exactly this kind of threat since 1996. Our approach to email security and phishing prevention goes beyond a one-time training video:

Client-facing security education, including real, de-identified phishing examples pulled from actual attempts against businesses like yours
Email security gateway configuration and auditing (Microsoft 365, Google Workspace, and third-party gateways) to catch spoofed domains and lookalike senders before they reach an inbox
Ongoing phishing simulation and awareness content, built to reflect current attack trends rather than generic templates
Security risk assessments that evaluate your current email defenses, DMARC/SPF/DKIM configuration, and staff readiness

If your team handles vendor payments, invoices, or e-signature requests of any kind, a five-minute conversation now is a lot cheaper than a wire transfer that can’t be reversed.

Want a second set of eyes on your email security setup?

Contact P3C Technologies for a free Level 1 Security Risk Assessment and see exactly where a request like this one would have — or wouldn’t have — been caught.

*Keywords: DocuSign phishing email, is this DocuSign email real, DocuSign scam 2026, fake DocuSign invoice, business email compromise, phishing awareness training, email security West Bend WI, P3C Technologies, managed IT services Wisconsin, CPA firm cybersecurity.*