logo

Spamming Microsoft 365 Like It’s 1995 

ID: 5e217c82-ad16-5e43-961f-983eff155700

STIX ID: report--5e217c82-ad16-5e43-961f-983eff155700

Feed Name: Black Hills Infosec Blog

Date Published: 2023-12-14

Date Updated: 2026-04-27

Author: BHIS

...
...

This report presents research on abusing Microsoft 365 Exchange Online’s Direct Send smart host to spoof emails and deliver device code phishing messages, showing that default Exchange Online Protection produces inconsistent outcomes across tenants. Through controlled tests varying sender domains, encodings (ASCII, UTF-32, UTF-7), subjects, and IPs, the author demonstrates that messages alternately land in inbox, junk, or quarantine, heavily influenced by sender domain authentication (SPF/DKIM/DMARC) and proprietary Microsoft filtering. Header analysis highlights differences in spam confidence scoring, and large-scale tests confirm inconsistent filtering across tenants. The report recommends hardening by restricting Direct Send smart host usage to specific IPs or certificates and urges ongoing validation of inbound email defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.