---
title: "Frequently asked questions"
url: https://kysigned.com/faq
---

# Frequently asked questions

## How do I sign?

You sign by **forwarding the email we sent you**, the one the document is attached to. There is no account, password, or app.

1. Open the kysigned email in your inbox (the document is attached to it).
2. **Forward** it to the signing address shown in the email (`forward-to-sign@…`), and keep the attached PDF.
3. Type **“I sign this document”** as the very first line of your forward, then press **Send**.

Capitalization does not matter, but **keep the attachment**: the forwarded email must still include the original PDF, unchanged. Your email provider's invisible signature on that forward is what proves the message really came from you.

## I sent it to the wrong email, or forgot a signer: what now?

Fix it **directly on the document’s page** while it is still open, no need to start over.

1. Open the document on your dashboard.
2. Each signer has an **Edit** and a **Delete** control, and there is an **\+ Add signer** button. To correct a wrong address, edit that signer and change the email: we cancel the old request and send a fresh one to the new address. To drop someone, Delete them; to add a missing signer, Add them.
3. Each change re-sends only that one person's request, everyone else is untouched. You can keep adjusting until you **seal** the document.

Editing a signer who had _already_ signed simply asks them to sign again (their earlier signature is set aside); the shared document never changes, so no one else is affected.

## Why do senders need to sign in?

Your account is where your sent documents live. It is how kysigned knows which documents are yours, so you can track who has signed, receive the completed signing record, and keep your credits (your first 4 documents are free, no credit card needed).

You can prepare a document without signing in: the sign-in moment comes once, when you press **Send for signing**. A magic link to your email is the whole ceremony; there is no password and no separate registration, your account is created on your first sign-in.

**Signers never sign in.** The person you send a document to needs no account, no password, and no app: they just forward the email back with the signing phrase, and that is it.

## What exactly is “the signature email”? (sending it by hand)

Normally you just press **Forward** on the email we sent you. If you ever need to construct it by hand, here is exactly what the signing email is:

- **To:** `forward-to-sign@<the kysigned domain>`. The exact address is shown in your signing-request email.
- **Subject:** keep the original subject, it carries a routing tag in square brackets, e.g. `Signature requested: “Your Document” [ksgn-…]`. That `[ksgn-…]` tag is how we match your reply to the right document, so do not remove it (a leading `Fwd:` is fine).
- **First line of the body:** `I sign this document` (any capitalisation).
- **Attachment:** the original PDF we attached, **unchanged**. That attached document is the exact thing you are signing, so keep it on the email.

Send it from the mailbox the request was addressed to. Your email provider signs the message on the way out (this is called DKIM). That invisible signature, over your words and the attached PDF, is your signature.

## My signature wasn’t accepted because my email isn’t set up. What now?

You did everything right. Your signature couldn’t be accepted because your organization’s email domain isn’t set up to prove that its messages really come from it. That proof is a signature your email system adds to every message it sends, called **DKIM**. Only your organization’s email administrator can switch it on. It’s a one-time setting, so forwarding again won’t help until it’s on.

1. Send this to whoever manages your organization’s email: _“Please turn on DKIM email signing for our domain. Here’s how: https://kysigned.com/faq#email-setup”_
2. Once they confirm it’s on, forward the original signing email again, exactly as before.

**Need to sign sooner?** Ask the sender to send the document to a different email address of yours.

### Why turn this on (even if you never use kysigned)

- **Your mail reaches inboxes instead of spam.** Gmail, Yahoo and Outlook now require senders to prove their identity. Mail from domains that don’t sign is treated with suspicion, and mail sent in volume can be rejected outright.
- **It stops criminals from impersonating your domain.** Without DKIM, anyone can send email that looks like it comes from your organization. DKIM is also the foundation for DMARC, the policy that tells the world’s mail systems to block those fakes.
- **Your mail keeps working when it’s forwarded.** SPF, the other common check, breaks as soon as a message passes through a forwarder or a mailing list. A DKIM signature travels inside the message and stays valid.
- **Security reviews expect it.** Customer security questionnaires, cyber insurance forms and security rating tools all check for DKIM and DMARC. It’s one of the cheapest findings to clear.
- **It costs nothing and changes nothing for your users.** One setting in your admin console plus one DNS record. It only adds a signature; nothing about how people send or receive mail changes.

### Google Workspace

1. Sign in to the Google Admin console as a super administrator and go to **Apps**, then **Google Workspace**, then **Gmail**.
2. Open **Authenticate email** and select your domain.
3. Click **Generate new record**. Keep the 2048-bit key and the default prefix `google`, then click **Generate**.
4. At your DNS host, add a TXT record with the host name and value Google shows (the host is usually `google._domainkey`).
5. Back in the Admin console, click **Start authentication**. DNS changes can take up to 48 hours to be picked up.

Google’s full guide: [Set up DKIM](https://support.google.com/a/answer/180504).

### Microsoft 365

1. In the Microsoft Defender portal (`security.microsoft.com`), go to **Email & collaboration**, then **Policies & rules**, then **Threat policies**, then **Email authentication settings**, and open the **DKIM** tab.
2. Select your domain and switch its toggle toward **Enabled**. Microsoft then shows the two CNAME records you need.
3. At your DNS host, create both CNAME records (`selector1._domainkey` and `selector2._domainkey`) with the values shown.
4. Once Microsoft detects them, switch the toggle to **Enabled**.

Microsoft’s full guide: [How to use DKIM for email in your custom domain](https://learn.microsoft.com/en-us/defender-office-365/email-authentication-dkim-configure).

### Other email providers

Look for a DKIM or “email authentication” setting in your provider’s admin console. The pattern is the same everywhere: generate a key, publish the DNS record it shows you, then switch signing on.

### How to check it worked

Forward the original signing email again, with “I sign this document” as its first line. When it’s accepted, you get a confirmation right away.

**Sending from an alias?** If you send as this address through a different email account (a “send mail as” alias), sign from the mailbox that owns the address instead.

## How do I verify a completed document?

Everything you need is inside the one signing-record PDF you received. There are three levels, depending on how thorough you want to be:

- **Level 0, just open it.** The signing record opens cleanly in any PDF viewer (no certificate banner, no “validity unknown” warning, no red-X), and its first page shows each signer's verdict at a glance.
- **Level 1, read the signature page.** That first page is an attestation-grade summary of who signed what, and when.
- **Level 2, re-run the math yourself.** Drag the signing record onto [the verify page](/verify) (or use the command-line verifier). It extracts the embedded evidence and checks every signature on your own computer, offline, forever, and even if kysigned no longer exists. **kysigned is not part of the trust set.**

## I am the sender, how do I know my signers got my exact document?

Two ways, and they stack. First, the finished signing record is **tamper-evident on its own**. Drop it on [the verify page](/verify) and the **“document matches”** check confirms every signer's email is cryptographically bound to the exact PDF they received, your document together with their cover page, and the verification code confirms the whole record is intact. If a single byte of the document had been altered anywhere along the way, verification would fail. So verifying already proves the document everyone signed was not tampered with.

Second, to confirm that document is specifically _your_ file, that nothing was swapped between your upload and your signers, use the [hash-check tool](/hashcheck). Drop your original PDF on one side and the signing record on the other, and it confirms, right in your browser, that your document is the one carried inside, byte for byte. You can check a sign-request PDF a signer received the same way. It is your own independent check that what went out is exactly what you uploaded, with no need to trust us.

## What does a kysigned signature prove?

Honestly and precisely: it proves that **someone with control of a specific mailbox signed exactly this document**, at a time backed by independent timestamps. It is evidence of mailbox control over an exact document, not a claim about the legal identity of a named person.

The proof is your email provider's own signature over your forwarded message and the attached document. Anyone can check it without trusting kysigned: your provider, the public key archives, and the timestamp authorities are the trust set; we are not.

## Why can't I just pay $0.25 for a single document?

Frankly, charging and accounting for a $0.25 payment by credit card does not make sense: the card-processing fees on a payment that small would cost more than the payment itself. So today you buy a small pack of credits up front (for example, **$5 for 20 documents**), and each document you send draws one credit. Credits never expire.

Want exactly one document, no pack? That exists today: **x402** (an open standard for instant, pay-as-you-go web payments) lets you pay $0.25 for a single document directly, with no top-up and no account setup. AI agents get it built in through the kysigned MCP tools, and any x402-capable client can pay at the API itself; the [agent docs](/llms.txt) show the flow.

## Can I run my own kysigned?

Yes. kysigned is open source under the **Apache 2.0 license**, so you can deploy your own instance with your brand, your domain, and your billing model. It runs on [run402](https://run402.com), the same platform behind kysigned.com, and every instance produces the same independently verifiable signing records.

See [hosted vs your own kysigned](/saas-vs-repo.html) for what changes and what stays the same, or start straight from the [GitHub repository](https://github.com/kychee-com/kysigned).

## Is there a maximum file size?

Yes, each PDF can be up to about **3 MB**. Larger files are declined when you upload them, with a note to compress or split the document.

It is on the smaller side because every signer's evidence includes a full copy of the document (that is what makes the finished signing record independently verifiable), so it grows with both the file size and the number of signers. If your document is larger, compress it (most PDFs shrink a lot) or split it and send each part for signing separately.

## Can I send several documents for signing at once?

No. Each signing request covers one document, on purpose. You sign by typing **“I sign this document”**, a single statement of intent, so each request holds a single PDF for that statement to refer to. Allowing several documents would blur what each signer actually agreed to.

If you have more than one, you have two choices: combine them into a single PDF (as long as it is within the size limit above) and send that as one document, or send each document separately.

## Which languages can I use for document and signer names?

The document title and signer names we print on the cover and signature pages support **Latin (including accents such as é, ü, ñ, and ł), Greek, Cyrillic, Hebrew, and Arabic**. Hebrew reads right to left, as you would expect. Arabic letters appear in their standalone shapes rather than joined cursive, so a name stays fully legible even though it is not calligraphically connected.

**Chinese, Japanese, and Korean names are not supported yet**, because they need a much larger font and extra rendering we have not added. If a name or title uses a character we cannot render, we tell you as soon as you send the document and name the exact character, so nothing is ever printed as an empty box. More scripts may follow.

This limit applies only to the short _names we print_. The **document you upload is never re-typeset by kysigned**: its contents travel exactly as you sent them and can be in any language, including Chinese, Japanese, and Korean. Only the name fields on the cover page follow the list above.

Still stuck? Contact the person who sent you the document, or see [how signing works](/how-it-works).
