logo

Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials

ID: 424d9070-b206-5f18-9adb-98cdfc6e61f0

STIX ID: report--424d9070-b206-5f18-9adb-98cdfc6e61f0

Feed Name: GBHackers

Threat Score
65/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Mayura Kathir

...
...

ReliaQuest describes a Microsoft 365 mail-flow bypass where attackers send messages with an empty envelope-sender (MAIL FROM:<>) to evade the RejectDirectSend check and appear to be internal; Exchange Online accepts such messages at transport level (though downstream spam checks may still flag them), and the technique has been observed in phishing campaigns targeting executives and finance staff. The report recommends keeping RejectDirectSend enabled but adding stronger compensating controls (IP-restricted inbound connectors or TLS-authenticated connectors), removing allow-list overrides for high-risk users, and detecting messages with Return-Path:<> combined with an internal-looking From: address where SPF/DKIM/DMARC fail.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.