Short answer: Open the signing link from the platform's own notification, confirm the sender and the document version, apply your signature where the fields are placed, complete any identity check, then download the completed copy together with its audit record. If the sender sent a PDF attachment instead of a tracked link, read the security section below before you sign and reply with it attached.
The two situations feel similar and are handled differently. A tracked signing request carries its own identity and tamper evidence; a plain PDF attachment carries none, and the act of signing and replying with it is where most of the avoidable problems start.
This guide covers both — the safe path through a tracked request, and what to watch for when the document arrives as a bare attachment.
The three ways an emailed document reaches you
Which one you received determines what you should do, and how much evidence exists afterward.
| Delivery method | What it looks like | Evidence it creates | What to do |
|---|---|---|---|
| Tracked signing request | An email from a signing platform with a link and an envelope or request ID | Identity log, timestamp, document hash, audit trail | Sign through the link, then download the completed package |
| Portal or account task | A notification that a document is waiting inside a platform you log into | Same as above, tied to your authenticated session | Sign in by typing the platform's address yourself, then open the task |
| Plain PDF attachment | The document itself, attached, with no platform involved | None beyond your email metadata | Consider moving it to a tracked flow before signing |
The third row is the one worth pausing on. Signing a PDF and replying with it attached does produce a document with a mark on it, but it leaves no record of when you signed, which version you signed, or how anyone can tell afterward that the file was not altered in between.
Step by step: signing a tracked request
- Verify the request before you touch it. Check the sending domain against the platform's published domain list, and confirm you were expecting a document from this sender. Real signing notifications do not ask you to enter your email password.
- Open the document from the original notification, not from a forwarded copy and not from a re-downloaded attachment someone added to a reply chain.
- Read the whole document, including the version marker. Confirm the title, the date, and the revision match what you agreed to. If the document references a price, a term, or a scope that changed in the last round of edits, stop and ask before signing.
- Check the fields assigned to you. Most requests place your name, date, initials, and signature fields already. If a field is missing or points at the wrong party, ask the sender to correct the envelope rather than working around it.
- Choose the signing method the document calls for. A typed or drawn signature is fine for routine agreements; documents with regulatory or high-value consequences may require a certificate-backed signature or a verified identity.
- Complete the identity check if one is required. A one-time code is the common case; a government ID or a certificate is the higher tier. Do not have someone else complete the check on your behalf — that single step is what makes the rest of the evidence meaningful.
- Download the completed copy and the audit trail. Take both, not just the PDF. The trail is what lets you answer "when did this get signed, and by whom" months later.
Telling a real signing request from a phishing lookalike
Signing-platform notifications are a favorite phishing disguise precisely because people are conditioned to click them. The verification habit is cheap and catches nearly all of them.
- Check the domain, not the display name. Look at the actual sending address and the domain inside the link. Signing platforms publish the domains and IP ranges they send from; compare against that official list rather than trusting the branding in the message.
- Type the platform's address yourself if the message contains a request or envelope ID. Look the ID up in a session you started, rather than following the link.
- Treat password prompts as a red flag. A signing request authenticates you to sign, not to a password form embedded in an email. Legitimate flows send you to the platform's own sign-in.
- Watch for urgency and mismatched context. A document you were not expecting, from a sender you do not recognize, with a deadline measured in hours, is the standard shape of the attack.
- Confirm through a channel you already had. If anything feels off, call or message the sender using contact details you already hold — never the reply-to address in the suspicious message.
Recorded walkthroughs of the specific tells are in How to Spot a Fake DocuSign Email and, for the lookup-first version of the same check, Verify a Suspicious DocuSign Email Safely.
When the document arrives as a plain attachment
If it is an Outlook attachment rather than a tracked link, the mechanics differ but the goal is the same: leave a record. The add-in route is documented in How to Sign an Email Attachment in Outlook Using the DocuSign Add-in, and the platform-neutral steps for marking up a PDF are in How To Sign A PDF: Step-by-Step with Security and Audit Evidence.
Whichever route you take, three rules hold:
- Do not edit the document body. Add your signature only, so the recipient can diff the file against the version they sent.
- Reply to the original message rather than starting a new thread, so the attachment history stays in one place.
- Send the file back as a new attachment with your mark, and keep your own copy of what you sent.
Then ask whether the counterparty will accept the result. If the agreement matters, converting the exchange to a tracked envelope afterward is usually worth the extra step — it costs a few minutes and replaces an email thread with evidence.
Fixing the mistakes that cause most of the trouble
- Round-tripping a PDF. Sign-and-reply leaves no chain of custody. Use it for low-stakes acknowledgments, not contracts.
- Forwarding the signing link. Many platforms bind a link to the recipient's email address. Forwarding can either block the intended signer or let the wrong person sign under their identity. Use the platform's delegation feature when a colleague needs to sign instead.
- Signing the wrong revision. In any negotiation with multiple drafts, the version you sign must be the one both parties agreed to. Check the revision marker every time.
- Signing from a shared device or shared account. Attribution collapses if several people use one login. If your team shares a signing account, that is worth fixing before the next agreement.
- Skipping the consent disclosure. It is easy to click past a long block of text at the start of a signing session. That block is the record that you agreed to transact electronically, and it is part of what makes the signature hold up.
Disclaimer
This article provides general guidance on handling documents received by email and is not legal advice. Whether a specific agreement may be executed electronically, and what evidence will satisfy a court or regulator, depends on the document, the state, and the parties involved — your counsel should advise on the specific matter.
Why a Signing Link Beats an Emailed PDF
The risk in the "just reply with a signed PDF" flow is not the signature — it is everything else. Whoever opens the attachment decides which version of the document to sign, on which device, and from which network, and the sender is the last person to know.
FaDaDa's Nota Sign replaces that exchange with a tracked link. The recipient opens the document in a browser session the platform controls, the system records what was on screen at signing time, and the completed package comes back to the sender as a record rather than as an email reply to be filed. Recipients do not install anything, and the sender does not have to match a returned filename to the original.
If your team still ends every agreement with "please reply with a signed PDF," send us one of those live exchanges and we will pair it onto a tracked envelope so you can compare the two.









