Skip to content

EricN Publications

Publications by Eric Niewoehner

Menu
  • Non-Fiction
    • A God Thing
    • The Advent Conspiracy
    • The Alaskan Chronicles
    • Econ 101 — Basic Economics
    • Lessons Learned
    • Oakland
    • Old Friends
      • The Ideological Origins of the American Revolution
      • The Road to Serfdom
    • The Pandemic Journal
    • Thinking Out Loud
    • The Garden of the Gods
    • Iconium
    • When Few Were Watching
  • Fiction by Eric Niewoehner
    • The Missouri Chronicles
      • Before Lawrence
    • The Jesus Chronicles
  • Technology Publications
    • The Spam Chronicles
    • Technology Blogs
    • The Facebook Safe Space
    • The Windows Chronicles
    • Technical Documentation
    • The Tech Community
    • Introducing Substack and Locals.Com
  • Subscribe
  • More
    • About
    • Categories
    • Contact
    • Social Media
Menu
DocuSign Sign

The DocuSign Pretender

Posted on September 3, 2026September 3, 2026 by Eric Niewoehner

I recently received a message declaring “Your document is ready.” At the top of the message was the apparent sender: DocuSign. Alas, this scam was easy to break apart, but it can happen to even the most watchful. Several things will be looked at in this case:

  • The Message
  • The Email Address the scammer used to reach my mailbox
  • The Links within the message
  • A look at the message header
  • Finally, what we can learn from this

The Message

Messages of this sort are effective if they happen to fall within a certain context.

  • You happen to be doing official business. Odds are quite good that most of us are doing something officially sometime during the month, and almost all the agencies I correspond with will offer the option of a digital signature. This is where companies like DocuSign are quite helpful. If a message slips in from a scammer under this situation, you may click before you think.
  • It is something you do not do often. While DocuSign is convenient and trustworthy, it is also something not done frequently by most people. Thus, the “mechanics” of the process may be unfamiliar. You may not recognize the scammers “hook” until it is too late. Before you know it, you have released an ID and password to a specific account.
  • You do your business on the phone. I come back to this with almost every article I post. A quick question in Duck-Duck-Go will produce a result showing 15% of Americans use only their cell phones for commerce. My estimate, however, is that the number is much larger primarily because the phone is quick and convenient and we can conduct our business while we are on the move. This sort of message will not provide many clues, just one large predominant blue button saying “Review Document,” that covers the entire screen of the phone.

The Email Address

Email Graphic
Multiple E-mail addresses can be used to tighten security

Most people I know have only one, maybe two, e-mail addresses. In “Email: A Method to the Madness,” I present the idea of using multiple e-mail addresses based on their primary purpose. In this instance, the suspicious message was flagged simply based on the fact it was sent to the address I use for banks, investment firms and the government. A message like this stands out. In essence, don’t use the same e-mail address you use with your bank on a website catering to greeting cards.

Still – it was a good ruse. And, obviously, even the safest e-mail address can be bought for a price.

The Links

The next thing I check are the links. This is where doing commerce on your desktop computer is much preferred over a smartphone. Simply by hovering over a link, you can see appearing along the bottom of the screen the name of the link. No need to click on it.

In my case, it was a link to docusign.commercey.com. You would think it would point to docusign.com, but this is a simple technique scammers use to fool people by adding the name of a legitimate company to the front of an URL that actually points to the scammers website. What’s funny about this particular message is that all the links point to the same URL, regardless of the topic. A bit lazy.

Who is commercey.com?

Next, let’s see what we can learn about “commercey”.

My first stop is at WHOIS to check domains. The information is rather interesting. The phrase “commercey” is a bit dicey, but this domain has been registered since 2013. Most fraudulent URLs are here today and gone tomorrow. But this one has been around for thirteen years. Yet when you look at the contact information for the registrant, it is a proxy. The true identity of the registrant is masked. So what we have here is a fraudster using a domain that has been around for a long time, with no clue as to who actually owns commercey. Doesn’t help Commercey.

Whois Logo
Whois is a great place to check a website’s registration

I reviewed the commercey homepage using the view-source tool in Firefox.

view-source:https://commercey.com/

Here you read an explanation of the business mission of Commercey.

Commercey’s E-commerce Shopping Cart is Fast and Easy to Use! Set up an Online Store for WordPress, Drupal, Facebook and Much More! Start Selling Now

This begins to solve the mystery of how a fraudster has piggy-backed an otherwise legitimate operation. Commercey is an E-Commerce site web designers use.

So lets look further into the entire URL, adding “docusign.”

view-source:https://docusign.commercey.com/

Hilarious.

Service Temporarily Unavailable. Please try again later.

So kudos to Commercey. This scam was squashed within hours of receipt.

What About The E-mail Headers

I have previously used E-mail Headers as my starting point in analyzing questionable e-mails, but I have discovered that too many of the details can be masked by trafficking fraudulent activity through legitimate mail handlers and inserting false Reply-to addresses. The links usually betray more of the intent of the scammer. E-mail headers can drag into the picture innocent parties.

If you are not familiar with e-mail headers, you can expose them by right-clicking over the message you are reading and selecting “View Source” ( I am using Thunderbird).

X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-Path: <bounce+b5e5c9.089a5-myemail@healthfulpursuit.com>
Authentication-Results: perfora.net; dkim=pass header.i=@healthfulpursuit.com
header.s=smtp; spf=pass smtp.mailfrom=
bounce+b5e5c9.089a5…@healthfulpursuit.com; dmarc=pass
header.from=healthfulpursuit.com policy.dmarc=none; iprev=pass
policy.iprev=69.72.43.12
Received: from v512.v5c0b6788.use4.send.mailgun.net ([69.72.43.12]) by
mx.perfora.net (mxeueus003 [74.208.114.66]) with ESMTPS (Nemesis) id
1M6EGC-1wyfVn0lQG-00DQsl for <myemail>; Mon, 31 Aug 2026
05:11:43 +0200
DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=healthfulpursuit.com; q=dns/txt; s=smtp; t=1788145902; x=1788153102;
h=Subject: Subject: To: To: From: From: MIME-Version: Content-Type: Message-Id: Date: Sender: Sender;
bh=QQ59H9ssgPkOFXfeZCMLKTK3TKgxu6q7ZThSnXMwWcU=;
b=C6a+jJOYmmazAiRA+OtXJJ1mOrJkymCOU2E2/z7cK7wErgH/3F/GIS3Y/y1de7ITVnGgVo3dOpTbwSUlO6/vSTzaX0JpdpA2uB0U5gGjrEEN6CsA1bcYLQNYfuvwPE5qYlg21+wNZt78fdg6uX41us5cp6RX+JREgfVLt0kfeWk=
X-Mailgun-Sid: WyI1NWYyMCIsInNhZmVAbmlld29laG5lcnMubmFtZSIsIjA4OWE1Il0=
Received: from v990376002.local (unknown [65.111.28.25]) by
efda66be99d8ccf263d823feadc39e8b5359ad180ac14f2f331762a08144cf11 with SMTP id
6a94f0eee201d08cdf822601 (version=TLS1.3, cipher=TLS_AES_128_GCM_SHA256);
Mon, 31 Aug 2026 03:11:42 GMT
X-Mailgun-Sending-Ip: 69.72.43.12
Sender: noreply@healthfulpursuit.com
Date: Mon, 31 Aug 2026 03:11:42 +0000
Message-Id: <20260831031142.2bf50753ac930995@healthfulpursuit.com>
Content-Type: multipart/alternative; boundary=”===============6445047643925209058==”
MIME-Version: 1.0
From: Noreply <noreply@healthfulpursuit.com>

From

Let’s start from the bottom. Most people only see this address when reading a message. But this a case where the sender has inserted a spoofed address, using a legitimate business operation. Using WHOIS, healthfulpursuit.com has been registered since 1997. The scammer has used this ruse to give the impression this pertains to a health care service that you may or may not be aware of. With the emergence of third-party health care managers and service providers, it is easy to use this deception.

Thunderbird Logo
Need an E-mail program? Try Thunderbird. It is free.

Message-Id

Message-Ids guarantee a unique identification of any message sent by a mailserver. But message-ids can be code-generated by the scammer, inserted into the header.

Sender

In this case, the Sender and “From” are the same, but in many cases they can differ. Again, this can be spoofed.

X-Mailgun-Sending-Ip: 69.72.43.12

This is interesting. This provides a clue as to the technique the scammer was using to generate the message. Mailgun is an e-mail service, providing platforms and tools for sending messages. The IP address is owned by Mailgun. What’s valuable about this information is that it can be used to lodge complaints and de-activate the scammer’s account with Mailgun.

Received

While the message may have been generated and commenced by Mailgun, the actual message was received from IP address 65.111.28.25. Using AbuseIPDB, we can get a reading as to the source of this IP address, who owns it, and which router manages it. It is located in Berlin. What is also interesting is that at the time of this writing, the IP address had a 19% complaint rate and now climbing.

The Digital Signature

At this point, the sender generates a digital certificate. From where this signature was derived was a bit of a mystery until you read ahead under Authentication-Results and note that the signature was authenticated from Mailgun, not Healthful Pursuit. Note the IP address. Interesting.


DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=healthfulpursuit.com; q=dns/txt; s=smtp; t=1788145902; x=1788153102;

Authentication-Results: perfora.net; dkim=pass
…

iprev=pass policy.iprev=69.72.43.12

But Then There is the Bounce

Also included in “Authentication-Results” is the status of the “From” address that was inserted above. It bounced. But rather than derail the message or flag it as Spam, it continued down its merry course because the authentication tags remained intact in regards to the e-mail servers themselves (DKIM=pass). But the address at healthfulpursuit.com was not verified. Go figure.

smtp.mailfrom= bounce+b5e5c9.089a5-myemail@healthfulpursuit.com

Message Status

Thunderbird is designed under the Mozilla Foundation. So these two items are inserted into the header to provide Thunderbird with information regarding the message’s status.

X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000

The first item indicates it has been read. The second item essentially states nothing else has been done with this message.

Solutions

The Good News

This is now happening faster than in the past, but this message was essentially zapped at the source within hours of its posting. Someone along the line pulled the plug: Mailgun or Commercey.

Grading Scale

I have always been an advocate for a grading scale that is easy for the reader to view and decide for themselves whether a message is legit or not. Spam filters are far from perfect. I believe that AI will help contribute to a faster, more dynamic system-wide spam filtering mechanism, but AI will also be used by criminals. The same techniques that can ferret out criminals can be used to analyze your own vulnerabilities. So it all returns to “what do you think?” Having a score that indicates the trustworthiness of a document is worth considering. What weighs against this message?

  • The “bounce” was certainly non-standard
  • Owner of Commercy URL is masked
  • A “reply-to” or “return-to” address is not verified
  • Sender’s IP address produced a 19% reporting rate at AbuseIPDB
  • Scammer used multiple domains to construct the message: Mailgun, Commercey and Healthfulpursuit.

From a technical perspective, that was about it. The rest is from the human perspective, what a person can perceive by observation.

Because Mailgun, Commercey and Healthful Pursuit are legitimate operations, this message would most likely have received a high grade in the technical sense. So grading does not solve every riddle.

The fact that the header recorded a trail of mail service providers that were DKIM verified also made this message appear more legitimate from a technical perspective. This may demonstrate a weakness of the DKIM structure, where a scammer can use a legitimate mail service provider like MailGun to mask criminal activity, hosted by a legitimate web provider like Commercey.

Resources

  • WHO
  • AbuseIPDB
  • “Email: A Method to the Madness”
  • Mailgun
  • Healthful Pursuit
  • “Email Headers Made Easy – How To Read and Understand Them,” ICDSoft, May 5, 2023
  • MXToolbox
  • “Understanding the source code of a malicious email,” Spamhaus Project, September 29, 2020
  • “Thunderbird’s X-Mozilla-Status and X-Mozilla-Status2 flags,” Vincent Bernat, June 15, 2022
  • “What all the stuff in email headers means—and how to sniff out spoofing,” Ars Technica, by Jim Salter, August 7, 2019


© Copyright 2024 to Eric Niewoehner

Comment (Subscribers Only)

Subscribe

Return to the Spam Chronicles

  1. Home
  2. Technology
  3. The DocuSign Pretender

Tags: AbuseIPDB, Commercey, DocuSign, Eric Niewoehner, EricN, EricN Publications, fraud, Mailgun, spam, Spam Chronicles, Thunderbird, whois

Share
Share on Social Media
blueskyxfacebooklinkedintelegramemail

Related

EricN Publication Logo
  • Facebook page for EricN Publications
  • LinkedIn page for EricN Publications
  • Twitter page for EricN Publications

Featured Story: Before Lawrence

Two revolvers from the Civil War

Recent Posts

  • The DocuSign Pretender
  • Seattle
  • Wildflowers of Southeast Alaska
  • Circle of Friends
  • Journey of the Missing File

Trending Posts

EricN Publications Favicon

Historical Top Reads

Anatomy of a Fraudulent Health Care Claim
The Prairie I Own
Why the Facebook Safe Space?
Facebook Safe Space
Technology Blogs
Stranger Than Fiction – The Case of Mary Fulp
Old Friends Series
Sustainable Printing
Logic of Rebellion
Before Lawrence

Substack Logo

Top Reads on Substack

Doing Things Better
Stranger Than Fiction – The Case of Mary Fulp
A Loss of Will
Diagnosing DOGE: Bullet Points
Big Tech Cancellation: The Case of the Racist Doorbell

Linked In Logo (Small)

Top Reads in LinkedIn

Remembering COVID
Saving Cracker Barrel
Shutdown – Lay-offs
Art of the Massacre
Change Management

Facebook Logo with Safe Space

Top Reads on Facebook

Missouri Wildflowers
Bullet Points
Purge of the Probies
Facebook Safespace
Before Lawrence

Google Logo

Top Reads on Google

Stranger Than Fiction
The Garden of the Gods
Why the Facebook Safe Space
Anatomy of a Fraudulent Health Care Claim
Be Thou My Vision

Copyright Notice

All articles are copyrighted material from Eric Niewoehner.

© 2026 EricN Publications | Powered by Minimalist Blog WordPress Theme