Skip to main content
Trust Center

Alerts and updates

Alerts RSS Feed

Subscribe using the Docusign Trust Center Alerts RSS feed URL: https://www.docusign.com/trust/alerts/feed.
Add an RSS reader extension to your browser (Chrome, Firefox), or enable via Outlook on a PC.

Planned Disaster Recovery Exercise for eSignature Azure Australia Production - October 17, 2026
10/17/2026

Docusign will undertake a planned disaster recovery exercise on Saturday, October 17, 2026 from 8:00 PM PST to 10:00 PM PST (Sunday, October 18, 2026, 3:00 AM to 5:00 AM UTC). The scope of this exercise is to perform a regional full-platform failover of eSignature Azure Australia production environment.

This exercise is not expected to cause downtime or impact eSignature services, however we are notifying customers as a precautionary measure.

Please contact DocuSign Support if you have any questions or concerns, and check back here for any updates regarding the schedule.

Planned Disaster Recovery Exercise for eSignature Azure Canada Production - September 12, 2026
09/12/2026

Docusign will undertake a planned disaster recovery exercise on Saturday, September 12th, 2026 from 8:00 PM to 10:00 PM PST (Sunday, September 13th, 2026 from 3:00 AM to 5:00 AM UTC). The scope of this exercise is to perform a regional full-platform failover of eSignature Azure Canada production environment.

This exercise is not expected to cause downtime or impact eSignature services, however we are notifying customers as a precautionary measure.

Please contact DocuSign Support if you have any questions or concerns, and check back here for any updates regarding the schedule.


New Docusign Status Center: Subscribe by September 1 to Receive Updates
09/01/2026

New Docusign Status Center: Subscribe by September 1 to Receive Updates

Docusign is transitioning to a new status center experience: health.docusign.com/status. Explore the upgraded site, featuring a fresh user interface and updated notifications. To continue getting notifications, you’ll need to subscribe to the new site. 

Here’s what you need to know:

Planned Disaster Recovery Exercise for eSignature Azure Japan Production - August 22, 2026
08/22/2026

Docusign will undertake a planned disaster recovery exercise on Saturday, August 22, 2026, from 9:00 AM to 11:00 AM PST (4:00 PM to 6:00 PM UTC). The scope of this exercise is to perform a regional full-platform failover of eSignature Azure Japan production environment.

This exercise is not expected to cause downtime or impact eSignature services, however we are notifying customers as a precautionary measure.

Please contact DocuSign Support if you have any questions or concerns, and check back here for any updates regarding the schedule.

Planned Disaster Recovery Exercise for eSignature EU Production - August 22, 2026
08/21/2026

Docusign will undertake a planned disaster recovery exercise on Saturday, August 22, from 4:00 PM UTC to 6:00 PM UTC. The scope of this exercise is to perform a failover of eSignature in our EU production environment, testing the disaster recovery process.

This exercise is not expected to cause downtime or impact eSignature services, however we are notifying customers as a precautionary measure.

Please contact Docusign Support if you have any questions or concerns, and check back here for any updates regarding the schedule.

Planned Maintenance for CLM Prod AU S1 - Aug 1 2026
08/01/2026

Docusign will be conducting maintenance for CLM Prod AU S1 on Saturday Aug 1st, 2026 from 5 PM UTC to 8 PM UTC.

During the maintenance window, some product functions might be briefly unavailable for up to 10 minutes, including:

- UI previews
- Workflow steps
- Standard attributions
- Party agreement

Users might also encounter slower response times in the user interface during the window. Workflow processing will continue to function as expected during the maintenance window.

Please contact Docusign Support if you have any questions or concerns, and check back here for any updates regarding the schedule.

Fraud Alert: Phishing Campaign Impersonating Intuit QuickBooks
07/23/2026

Docusign has observed a phishing campaign that impersonates Intuit QuickBooks by sending fraudulent Docusign envelopes from look-alike email addresses. These messages prompt recipients to review unexpected invoices or remittance advice, tricking them into clicking malicious links or processing unauthorized financial requests.

While these notifications originate from the Docusign platform and appear authentic, these requests are not legitimate. Our team is actively working to mitigate this type of abuse and disrupt the activity behind these campaigns.

Examples to look for:

  • Subject Line: Complete with Docusign: Outstanding Remittance Advise & Inv. xslx

  • Sender Display Name (in message body): Accounts Payable

  • Sender Email Format (in message body): quickbooks-notification.intuit.com@[random_domain].com

Measures you can take to protect yourself and your data:

  • Check the Sender and the Message: Be cautious of unexpected emails, even if they appear to originate from Docusign, especially if they involve unexpected invoices, payment updates, or remittance advice.

  • Check Your Account Directly: If you receive an unexpected invoice or accounting notification, do not click links, scan QR codes, or call numbers listed inside the document or email. Instead, go directly to the official vendor or source (in this case, Intuit QuickBooks) using a separate, secure connection to verify the request.

  • Verify and Report Suspicious Activity: Safely access a document by going directly to docusign.com and using the Access Documents feature with the unique Security Code provided at the bottom of the email. If you receive a suspicious message, forward it as an attachment to verify@docusign.com, or use the Docusign Report Abuse feature or Report Abuse Form.

Fraud Alert: Credential Harvesting Scam Impersonating LastPass
07/23/2026

Docusign has observed a phishing campaign where attackers impersonate password managers like LastPass by sending fake emails disguised as Docusign notifications. These messages frequently claim that users "have 14 business days to review and accept the updated terms" to create a false sense of urgency. The goal is to trick recipients into visiting fake login pages designed to steal passwords and sensitive credentials.

While these notifications use Docusign branding and appear authentic, they do not originate from Docusign. Our team is actively working to mitigate this abuse and take down malicious sites associated with these campaigns.

Examples to look for:

  • Urgent Message Text: "have 14 business days to review and accept the updated terms"

  • Malicious URL/Link Redirect: https[:]//lastpasscompliance[.]com

Measures you can take to protect yourself and your data:

  • Check the Sender and the Message: Be cautious of unexpected emails, even if they feature Docusign or LastPass branding, especially if they demand you accept updated terms of service or compliance policies under a strict deadline.

  • Check Your Account Directly: If you receive an unexpected security or compliance notification, do not click links, open attachments, or enter your credentials into external web pages. Instead, go directly to the official vendor website via a separate, secure browser window to verify the request.

  • Verify and Report Suspicious Activity: Safely access a legitimate Docusign document by going directly to docusign.com and using the Access Documents feature with the unique Security Code. If you receive a suspicious message impersonating Docusign, forward it as an attachment to verify@docusign.com.

Planned maintenance for Insight - July 22-24, 2026
07/21/2026

Docusign will be conducting scheduled maintenance for Insight between July 22, 2026 to July 24, 2026. This maintenance will result in regional service disruptions during the following windows:

  • Insight US West and Northeast and Insight Europe (West, North, and Central) Production: Customers’ service will be unavailable on July 22, 2026 between 1 AM UTC to 7 AM UTC.

  • Insight US East Production: Customers’ service will be unavailable on July 23, 2026 between 3 AM UTC to 9 AM UTC.

  • Insight US Central Production: Customers’ service will be unavailable on July 24, 2026 between 3 AM UTC to 9 AM UTC.

We apologize for any inconvenience this may cause and advise users who encounter errors during these times to retry their activity after the maintenance window concludes.

Please contact Docusign Support if you have any questions or concerns and check back here for any updates regarding the schedule.

Deprecation of TLS 1.2 Ciphers
07/19/2026

As part of Docusign's commitment to maintaining the highest security standards, we are entering the final phase of our TLS 1.2 weak cipher deprecation. Following the initial removal of weak ciphers in February 2023, Docusign will discontinue support for the remaining two weak AES CBC ciphers on July 20th.

Impacted Ciphers

Effective July 20th, the following cipher suites will no longer be supported by Docusign APIs and endpoints:

  • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 (0xc028)

    • OpenSSL name - ECDHE-RSA-AES256-SHA384

  • TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA (0xc014)

    • OpenSSL name - ECDHE-RSA-AES256-SHA

Action Required

Customers must ensure their integrations, client applications, and third-party connectors are updated to support modern, secure cipher suites before July 20th.

  1. Review Custom Integrations: If you maintain a custom-built integration, ensure your server or client configuration is not hardcoded to exclusively use the impacted ciphers.

  2. Check Third-Party Vendors: If you use a third-party connector to connect to Docusign, please verify with your vendor that their solution supports modern TLS 1.2 or TLS 1.3 ciphers.

Please contact Docusign Support if you have any questions or concerns