Security for Docusign eSignature
Security is in Docusign’s DNA, and like all of our products, Docusign eSignature is researched, designed, and developed with security as a top priority.
This document outlines the security technologies, policies, and practices that protect your documents and data within Docusign eSignature, including information that enables you to configure security in accordance with the specific risk management and compliance requirements of your organization. For security details common to all Docusign products, visit product security on the Trust Center.
Physical and logical security
Docusign maintains around-the-clock onsite security with strict physical access control that complies with industry-recognized standards, such as SOC 1, SOC 2, and ISO 27001.
We also use world-class security software and hardware to protect the physical integrity of Docusign eSignature and all associated computer systems and networks that process customer data. We do this through a centralized management system that controls access to the production environment through a global two-factor authentication process.
This isolated production environment is protected by industry-leading network management systems, anti-virus software, and malware detectors. The anti-virus software is integrated with processes that automatically generate alerts to Docusign’s cyber incident response team if potentially harmful code is detected.
Security testing and vulnerability management
The quality and integrity of Docusign eSignature is ensured by a formal product development lifecycle that includes secure coding practices in accordance with OWASP. Rigorous automated and manual code reviews are designed to pinpoint security weaknesses. We also perform internal and external vulnerability scans and penetration tests against the Docusign eSignature production environment. Any identified weaknesses from these industry-compliant tests are remedied in a commercially reasonable manner and in a timeframe commensurate with their severity
Security monitoring
We monitor Docusign eSignature from both an operational and a security perspective. Intrusion prevention and detection events are logged, and tailored alerts are sent to our operations and security teams to ensure that Docusign eSignature can be used without security exposure from any location by those authorized to access it.
Storage, encryption, and disposal
To ensure your data stays protected, Docusign follows industry best practices to:
Logically separate individual customer data
Encrypt customer data—all data access and transfer activities use HTTPS and other secure protocols, such as SSL, SSH, IPsec, SFTP, or secure channel signing and sealing
Support only recognized cipher suites
Encrypt all documents with AES 256-bit encryption or the most recent FIPS-approved methods
Provide non-repudiation for all documents generated and signed using Docusign via a Certificate of Completion
Maintain a data disposal and re-use policy for managing data assets
Implement processes for equipment management and secure media disposal
Business continuity and disaster recovery
Docusign maintains written business continuity and disaster recovery plans that ensure the continuing availability of Docusign eSignature. The continuity plan includes crisis management, business recovery, and infrastructure elements, and we test both plans on an annual basis in accordance with ISO 27001 controls.
Configurable security features
Docusign eSignature offers the following customer-configurable features:
Multi-factor authentication provides an additional level of assurance that only those authorized to access Docusign eSignature and associated documents can access them
Role-based authorization for all business transaction types enables you to designate access to specific individual
Allowlists for Docusign eSignature service
Our top priority is to make your Docusign eSignature experience safe and secure, and it’s our intention to provide the most robust and reliable service possible to enable your business transactions. We also want to proactively share information that may be of interest to you regarding our service and understand the requirement to configure security to the needs of your organization.
Docusign customers should configure their spam filters and other software to allow for the following allowlisted domains to be accepted. They should also explicitly allow Internet addresses advertised by Docusign eSignature. It’s important to keep up-to-date with our current IP address ranges.
Domains
We recommend allowlisting all subdomains under the following domains:
.docusign.com
.docusign.net
Akamai CDN
To enhance network performance and security, Docusign eSignature uses Akamai CDN for static content distribution. Docusign browser applications use outgoing connections to docucdn-a.akamaihd.net and ronp-a.akamaihd.net.
Docusign endpoint IP addresses
If customers only need to allowlist the Docusign endpoint, the following IP addresses apply:
North America-based and demo accounts (current and continuing):
IP range: 209.112.104.1 - 209.112.107.254
CIDR notation: 209.112.104.0/22IP range: 64.207.216.1 - 64.207.219.254
CIDR notation: 64.207.216.0/22IP range: 162.248.184.1 - 162.248.187.254
CIDR notation: 162.248.184.0/22IP range: 20.12.134.144 - 20.12.134.159
CIDR notation: 20.12.134.144/28IP range: 20.253.118.128 - 20.253.118.143
CIDR notation: 20.253.118.128/28IP range: 20.7.89.192 - 20.7.89.207
CIDR notation: 20.7.89.192/28IP range: 20.171.224.80 - 20.171.224.95
CIDR notation: 20.171.224.80/28IP range: 20.12.135.144 - 20.12.135.159
CIDR notation: 20.12.135.144/28IP range: 20.253.118.160 - 20.253.118.175
CIDR notation: 20.253.118.160/28IP range: 20.7.90.48 - 20.7.90.63
CIDR notation: 20.7.90.48/28IP range: 20.40.31.128 - 20.40.31.143
CIDR notation: 20.40.31.128/28IP range: 20.12.135.160 - 20.12.135.175
CIDR notation: 20.12.135.160/28IP range: 20.253.118.176 - 20.253.118.191
CIDR notation: 20.253.118.176/28IP range: 20.7.90.64 - 20.7.90.79
CIDR notation: 20.7.90.64/28IP range: 20.171.224.16 - 20.171.224.31
CIDR notation: 20.171.224.16/28IP range: 52.177.241.22 - 52.177.241.23
CIDR notation: 52.177.241.22/31IP range: 20.236.201.102 - 20.236.201.103
CIDR notation: 20.236.201.102/31IP range: 20.241.243.190 - 20.241.243.191
CIDR notation: 20.241.243.190/31IP range: 20.125.64.104 - 20.125.64.105
CIDR notation: 20.125.64.104/31
Canada-based accounts (current and continuing):
IP range: 52.237.17.101
CIDR notation: 52.237.17.101/32IP range: 52.237.17.162
CIDR notation: 52.237.17.162/32IP range: 52.235.28.220
CIDR notation: 52.235.28.220/32IP range: 52.235.31.13
CIDR notation: 52.235.31.13/32IP range: 52.233.23.113
CIDR notation: 52.233.23.116/32IP range: 52.233.23.116
CIDR notation: 52.233.23.113/32IP range: 4.248.45.198
CIDR notation: 4.248.45.198/32IP range: 4.248.45.199
CIDR notation: 4.248.45.199/32IP range: 20.175.137.48 - 20.175.137.63
CIDR notation: 20.175.137.48/28IP range: 20.220.119.224 - 20.220.119.239
CIDR notation: 20.220.119.224/28IP range: 20.175.137.208 - 20.175.137.223
CIDR notation: 20.175.137.208/28IP range: 20.220.119.240 - 20.220.119.255
CIDR notation: 20.220.119.240/28IP range: 20.175.138.160 - 20.175.138.175
CIDR notation: 20.175.138.160/28IP range: 20.220.119.112 - 20.220.119.127
CIDR notation: 20.220.119.112/28IP range: 20.175.152.220 - 20.175.152.221
CIDR notation: 20.175.152.220/31IP range: 52.229.68.132 - 52.229.68.133
CIDR notation: 52.229.68.132/31
European Union-based accounts (current and continuing):
IP range: 185.81.100.1 - 185.81.103.254
CIDR notation: 185.81.100.0/22IP range: 192.103.120.1 - 192.103.123.254
CIDR notation: 192.103.120.0/22IP range: 20.93.100.0 - 20.93.100.15
CIDR notation: 20.93.100.0/28IP range: 20.4.162.48 - 20.4.162.63
CIDR notation: 20.4.162.48/28IP range: 20.93.100.208 - 20.93.100.223
CIDR notation: 20.93.100.208/28IP range: 20.4.162.32 - 20.4.162.47
CIDR notation: 20.4.162.32/28IP range: 20.93.100.64 - 20.93.100.79
CIDR notation: 20.93.100.64/28IP range: 20.4.162.64 - 20.4.162.79
CIDR notation: 20.4.162.64/28IP range: 20.23.72.48 - 20.23.72.49
CIDR notation: 20.23.72.48/31IP range: 20.223.8.20 - 20.223.8.21
CIDR notation: 20.223.8.20/31
Australian-based accounts (current and continuing):
IP range: 13.72.248.93
CIDR notation: 13.72.248.93/32IP range: 13.72.249.142
CIDR notation: 13.72.249.142/32IP range: 13.70.141.103
CIDR notation: 13.70.141.103/32IP range: 13.70.136.159
CIDR notation: 13.70.136.159/32IP range: 13.75.155.180
CIDR notation: 13.75.155.180/32IP range: 13.77.4.99
CIDR notation: 13.77.4.99/32IP range: 20.190.119.162
CIDR notation: 20.190.119.162/32IP range: 20.191.245.233
CIDR notation: 20.191.245.233/32IP range: 20.28.254.160 - 20.28.254.175
CIDR notation: 20.28.254.160/28IP range: 4.200.136.64 - 4.200.136.79
CIDR notation: 4.200.136.64/28IP range: 20.28.254.240 - 20.28.254.255
CIDR notation: 20.28.254.240/28IP range: 4.200.136.96 - 4.200.136.111
CIDR notation: 4.200.136.96/28IP range: 20.28.255.64 - 20.28.255.79
CIDR notation: 20.28.255.64/28IP range: 4.200.136.16 - 4.200.136.31
CIDR notation: 4.200.136.16/28IP range: 20.92.143.132 - 20.92.143.133
CIDR notation: 20.92.143.132/31IP range: 20.70.124.140 - 20.70.124.141
CIDR notation: 20.70.124.140/31
Japan-based accounts (current and continuing):
IP range: 4.189.192.16 - 4.189.192.31
CIDR notation: 4.189.192.16/28IP range: 52.175.140.128 - 52.175.140.143
CIDR notation: 52.175.140.128/28IP range: 4.189.193.16 - 4.189.193.31
CIDR notation: 4.189.193.16/28IP range: 4.189.194.80 - 4.189.194.95
CIDR notation: 4.189.194.80/28IP range: 138.91.22.112 - 138.91.22.127
CIDR notation: 138.91.22.112/28IP range: 138.91.16.48 - 138.91.16.63
CIDR notation: 138.91.16.48/28
Docusign email IP addresses
If customers need to allowlist Docusign’s email IP addresses, the following apply:
North America-based and demo accounts (current and continuing):
IP range: 209.112.104.1 - 209.112.107.254
CIDR notation: 209.112.104.1/22IP range: 64.207.216.1 - 64.207.219.254
CIDR notation: 64.207.216.1/22IP range: 162.248.184.1 - 162.248.187.254
CIDR notation: 162.248.184.1/22IP address: 54.240.32.183
CIDR notation: 54.240.32.183/32
European Union-based accounts (current and continuing):
IP range: 185.81.100.1 - 185.81.103.254
CIDR notation: 185.81.100.1/22IP range: 192.103.120.1 - 192.103.123.254
CIDR notation: 192.103.120.1/22
Additional third-party providers email IP addresses
Customers that use static email IP range filters on their incoming email servers will need to add new IP addresses in the allowlist to prevent rejection of legitimate Docusign emails.
North America-based and demo accounts
IP range 54.240.115.126 - 54.240.115.137 and IPs:
161.38.201.204
161.38.201.205
161.38.201.202
161.38.201.203
European Union-based accounts
IP range 54.240.54.89 - 54.240.54.92 and IPs:
204.220.160.187
204.220.160.199
Support for Sender Policy Framework (SPF) record checking
To flag and quarantine malicious spam on mail servers, enable both Sender Policy Framework (SPF) lookup functionality and Domain-based Message Authentication, Reporting & Conformance (DMARC). The combination of these technologies helps protect against malware spam attacks. Learn more about SPF at http://www.open-spf.org/ and DMARC at http://www.dmarc.org/.