logo

Stop Spoofing Yourself! Disabling M365 Direct Send

ID: 4fc06ff7-5cee-555a-ae71-fd03a7b1138b

STIX ID: report--4fc06ff7-5cee-555a-ae71-fd03a7b1138b

Feed Name: Black Hills Infosec Blog

Threat Score
55/100

Date Published: 2025-08-20

Date Updated: 2026-04-27

Author: BHIS

...
...

This report explains that Microsoft 365's Direct Send is an unauthenticated SMTP path allowing attackers to send email appearing to originate from internal addresses within a tenant, outlines recent surge in abuse for internal impersonation/phishing, discusses testing caveats, and shows how to enable the public-preview 'Reject Direct Send' setting (Set-OrganizationConfig -RejectDirectSend $true) to block such misuse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.