Understanding the Risky allow-list policies detected for docusign.net risk

Understanding the Risky allow-list policies detected for docusign.net risk

If you don’t have Barracuda Email Gateway Defense (EGD) working properly in your environment, the following risks are not tested or displayed in BarracudaONE:

  • Risky allow-list policies detected for intuit.com

  • Risky allow-list policies detected for docusign.net

BarracudaONE displays this risk when it detects, through Barracuda Email Gateway Defense, that docusign.net is included in one or more allow-list policies. This configuration bypasses email filtering controls and exposes your organization to impersonation attempts, domain spoofing, malware delivery, and unwanted email.

Why this is a risk

Adding docusign.net to an allow-list policy means that emails appearing to come from that domain bypass normal email security filtering. Attackers commonly spoof legitimate-looking domains like docusign.net to impersonate the trusted Docusign electronic signature service. When docusign.net is allow-listed, these malicious emails are not filtered and can reach users' inboxes, increasing the risk of:

  • Phishing attacks—Emails designed to steal credentials or sensitive information by impersonating DocuSign notifications.

  • Business Email Compromise (BEC)—Spoofed document signing requests that appear to come from DocuSign.

  • Malware delivery—Malicious attachments or links disguised as legitimate DocuSign documents.

  • Domain spoofing—Attackers can send emails that appear to originate from docusign.net without proper authentication.

  • Credential theft—Fake DocuSign login pages designed to capture usernames and passwords.

Allow-listing broadly used domains like docusign.net significantly weakens your email protection and creates an exploitable gap in your security posture.

Identifying this risk

To help you identify the policies affected, BarracudaONE displays:

  • the number of policies containing the unsafe domain

  • the names of policies with the risk

  • the types of policies with the risk (Account-level, Domain-level, or User-level)

Resolving this risk

Resolving this risk involves reviewing and removing docusign.net from allow-list policies in Barracuda Email Gateway Defense.

For more information, see Risky Policies Detection and Remediation.

To resolve the Risky allow-list policies detected for docusign.net Risk
  1. In the left navigation menu, select Home Home.png.

  2. In the Start mitigating risks section, do one of the following:

    • Select the Risky allow-list policies detected for docusign.net risk.

    • Select another risk, then use the arrows to navigate to the Risky allow-list policies detected for docusign.net risk.

  3. Review the list of policies containing docusign.net in the Evidence section.

  4. Select Manage manage.png to open the Email Protection Risky policies page.

  5. Review each policy and follow the steps in Risky Policies Detection and Remediation to do one of the following:

    • remove docusign.net from the policy

    • delete the policy if it is no longer needed.

When all policies containing docusign.net are removed or updated, the risk auto-resolves within 6 hours.

If docusign.net is added back to any policy, the risk returns.

Once you have resolved this risk

Removing docusign.net from allow-list policies restores full email filtering for this domain and gives your environment:

  • Stronger phishing protection—Emails spoofing Docusign services are now properly filtered and inspected.

  • Reduced risk of domain spoofing—Attackers can no longer bypass filtering by impersonating docusign.net.

  • Better malware detection—All emails from docusign.net are scanned for malicious attachments and links.

  • Improved filtering effectiveness—Email protection can analyze message content, sender reputation, and authentication for docusign.net emails.

  • Consistent security enforcement—No gaps in filtering that attackers could exploit.

  • Better customer experience—Harmful or unwanted emails are filtered, reducing complaints.

  • Protection against document-based attacks—Fake Docusign requests are identified and blocked before reaching users.


We value your feedback.
If you have questions, suggestions, or feedback on our documentation, contact the Campus Product Documentation team.
For general product inquiries or technical support, please contact the global Barracuda Support team.