"You have a document waiting for your signature." It's one of the most convincing lines a scammer can send, because real e-signature requests look almost exactly like that. The goal of the fake version is usually to get you to type a password into a fake login page, or to open a harmful attachment.
The good news: a few quick checks catch nearly every fake. Here's what to look for, whichever e-signature service the message claims to be from.
1. Were you expecting a document?
Real signing requests come from someone you're already talking to: a buyer, an agent, a landlord, an employer. Before you look at anything else, ask yourself whether this matches a conversation you've actually had. A surprise contract from a stranger is the biggest red flag of all.
2. Check where the link really goes
On a computer, hover over the button without clicking. On a phone, press and hold the link to preview it. Then read the web address carefully, especially the part just before the first single slash. That's the real domain.
Scammers use tricks like extra words (revampsign.com.document-view.net), hyphens (revamp-sign-secure.com) or swapped letters (revampsiqn.com). Genuine Revamp Sign links open on revamp365.ai or revampsign.com, and nowhere else. Our verification page has side-by-side examples.
3. Real signing pages don't ask for your password
This is the check that stops most phishing. Revamp Sign never asks signers to create an account, log in, or enter a password. Your private link is all you need. If a "signing" page asks you to sign in with your email account, or to enter your email password to "view the document", close it.
The same goes for money. Signing a document never requires payment, card details, bank logins or a Social Security number.
4. Watch for pressure
"Sign within 2 hours or lose the deal." "Final notice." "Account suspended." Urgency is a scammer's favorite tool, because it stops you from thinking. A genuine sender will happily wait while you read the document, ask questions, or talk to an attorney.
5. When in doubt, go around the message
If anything feels off, don't reply to the message and don't use any phone number in it. Contact the sender using details you already had, such as a number saved in your phone or an email from an earlier conversation, and ask whether they sent you a document.
What if you already clicked?
- If you only opened a page and didn't enter anything, close it. Simply viewing a page is usually low risk.
- If you entered a password, change it right away wherever you use it, and turn on two-step verification.
- If you shared financial details, contact your bank or card provider.
- Report it to the FTC at ReportFraud.ftc.gov, and forward phishing emails to [email protected].
What a real Revamp Sign request looks like
A genuine request comes from a person or company you're dealing with. It arrives by email or text, and it links to revamp365.ai or revampsign.com. It opens the document straight away, with no login. Before your first field, you'll see a short consent screen about signing electronically, and then the page guides you through the fields that need you.