An AI assistant invents your phone number, title or address when an email needs them and the real values are missing from what it was given. Language models fill gaps with something plausible, and a signature block is a row of gaps. The reliable fix is to keep contact details out of the model's output entirely: the assistant writes the message, and your real signature is appended from a tool or a saved field that the model cannot edit.
What it looks like when an AI makes up your details
A competitor's phone number in the signature block
In r/claude, a user posted under the title "When drafting an email, Claude inserted my competitor's phone number in my signature block". Asked where the number came from, the assistant replied, as the poster quoted it: "I made it up. There is no phone number in any of the files". It had put the number into every document "without flagging that I was guessing."
A phone number for a letter to a court
On Claude Code's GitHub, a user reported that the assistant asked for their phone number to fill a signature block, and the suggested-reply feature offered "a specific, well-formed phone number that is not mine." They wrote that "the suggested number would have gone into correspondence with a court, over my signature." The reporter traced it to the suggestion feature, a separate part of the product from the assistant's own replies. The risk they named applies to any AI that fills fields: "A fabricated value of the right shape is indistinguishable from a real one for any field the user cannot verify by recognition."
"[Your Name]" left in the email
The milder version is the placeholder. A ChatGPT user asked for an email template and got "[your name] [your business name] [type of business] instead of actually putting in the correct info." On the Zapier forum, automated ChatGPT replies kept ending with "Best Regards, [Your Name]". An automation repeats the placeholder on every email it sends.
The wrong agent's name
Teams running several agents see a related failure. A developer running three agents, each with its own mailbox, described "prompt-level identity drift ("Sage signed as Ada")" and concluded that "every LLM-generated email needs a stable sign-off that can't drift via prompt contamination."
Why AI assistants make up contact details
OpenAI's research summary defines hallucinations as "plausible but false statements generated by language models", and argues that models hallucinate "because standard training and evaluation procedures reward guessing over acknowledging uncertainty." A phone number has a predictable shape, so a guess looks exactly like the real thing.
Three conditions make it likely in email:
- The signature is a template with slots. Name, title, phone and address each need a value, and a model asked to finish an email tries to fill every one.
- The real values are missing. The model has your name from the account, but your direct line, your new title and your office address were never in its context.
- Nothing tells it to stop. Without an instruction that a blank is acceptable, a placeholder or a guess are the only ways to fill the slot.
Anthropic's guide to reducing hallucinations starts with the same remedy: "Explicitly give Claude permission to admit uncertainty." It also suggests restricting the model to the information you provide, and ends with a caution that these techniques "don't eliminate them entirely."
Five ways to stop an AI from inventing your details
1. Give the agent your real signature through a tool
Have the assistant or workflow fetch a saved signature and append it after the body, unchanged. The model never types a phone number, so it cannot get one wrong. This works for MCP-connected assistants, n8n, Zapier, Make and your own code; the agent setup guide covers each.
2. Tell the model not to compose contact details
Put a plain rule in the system prompt or custom instructions:
Write the email body only. Never write a phone number, email address, street address, job title or company name unless it appears in the text I give you. Do not add a sign-off. If you need a detail you do not have, ask me.
The last sentence matters most: it gives the model a legitimate way to leave a blank.
3. Check every email before it sends
Add a send-time check that blocks an email which contains square brackets, a phrase like "Your Name", or a phone number that differs from the one in your saved signature. As one builder of an outreach agent put it, "a template that renders a lowercase name or an internal slug should refuse to send." In n8n, Zapier or Make this is one filter step before the send step.
4. Review external and legal email before it goes
Approval before sending catches what rules miss. Claude's Gmail connector, for example, asks for your approval before each send, reply or forward by default. For email to clients, courts, regulators or counterparties, keep that approval on. An agent's email that carries your name and signature block may be treated as signed by you; see can an email your AI agent sends bind you. Lawyers have specific duties here, covered in AI email and ABA Formal Opinion 512.
5. Give each agent its own fixed signature
When several agents send for one team, give each its own saved signature and its own key, so no prompt can sign one agent's email with another's name. One signature per AI agent explains the setup.
What Signatoro gives the agent
Signatoro is the saved signature in fix 1:
- Agentic sending. Claude, ChatGPT and other assistants connected to Signatoro's MCP server call
get_signatureand get the signature the person saved, ashtmlandtext, to append after the body. - API fetch. n8n, Zapier, Make and your own code call
GET https://signatoro.com/api/v1/signatureon every send. - No signature, no guess. If the person has not saved a signature, the API returns
404 no_signatureand the docs tell the agent to send without one and never invent one. The MCP tool answers that there is no saved signature yet and says where to make one. - Company details set by the company. In a company, the owner sets the company name, website, logo and compliance footnote for everyone. An assistant asked to change them through
update_my_signatureis told which parts the company controls and who changes them.
The model still writes the message, and the message can still be wrong. Signatoro covers the part that should never change from email to email: who you are and how to reach you.
Give your AI the real signature
Save your signature on Signatoro once. Your assistant fetches it on every email, so it never has to guess your phone number.
Frequently asked questions
Why did my AI make up a phone number in my email?
The email needed a phone number and the real one was missing from what the model was given, so it produced a plausible one. OpenAI's research says models are trained in ways that reward guessing over admitting uncertainty. Keep contact details out of the model's output and append your real signature from a saved source instead.
How do I make ChatGPT use my real name and details in emails?
Give it your details once, from a source it cannot rewrite. Paste a plain-text signature into custom instructions for drafts you finish yourself, or connect it to a signature service over MCP so it fetches the saved signature before sending. Tell it to write no contact details of its own.
How do I stop the AI from signing emails "[Your Name]"?
Tell the model to end the body without a sign-off, and have the workflow append your real signature after the body. In automations, add a check that blocks any email containing square brackets or "Your Name" before it sends.
Can I stop the AI from writing its own sign-off?
Yes. Instruct it to write the email body only, with no closing line or name, and let the mail app or the workflow add the signature. In Zapier, a Formatter step can cut any sign-off the model still adds. See two signatures on one email.
Who is responsible if my AI assistant sends a wrong phone number?
You generally are, since the email goes out from your account under your name. Courts have treated typed names and automatic signature blocks as signing an email, and no court we know of had ruled on one written by an AI agent as of October 7, 2026. Review external and legal email before it sends. This is general information, not legal advice.
Sources
Checked on 2026-10-07:
- OpenAI: Why language models hallucinate, September 5, 2025
- Anthropic: Reduce hallucinations
- Anthropic: Use Google Workspace connectors
- Reddit r/claude: When drafting an email, Claude inserted my competitor's phone number in my signature block
- GitHub, anthropics/claude-code: Suggested replies fabricate specific PII-shaped values (phone, case number, date), #85094, August 8, 2026
- Reddit r/ChatGPT: r/ChatGPT post on an email template with placeholders, December 30, 2024
- Zapier Community: Exclude ChatGPT Sign-off Line, June 6, 2024
- GitHub, openclaw/gogcli: gmail send: Add --signature flag to append Gmail signature, #180, comment of April 21, 2026
- Reddit r/AI_Agents: r/AI_Agents post on an outreach agent, July 20, 2026