Bypassed: Microsoft 365 Protection Exploited for Phishing Attacks
Security researchers at ReliaQuest have discovered a vulnerability in Microsoft 365's RejectDirectSend protection. The control, designed to stop unauthenticated Direct Send emails claiming to originate from an organization's own domain, can be bypassed using an empty SMTP envelope sender.
This allows attackers to send phishing messages that appear as if they were sent by trusted internal users. Even though the message originated externally and without authentication, the visible From address can display a trusted internal identity, such as 'IT Support' or an executive email address.
ReliaQuest conducted controlled testing and found that when using an empty envelope sender, the message was accepted for delivery despite RejectDirectSend's inspection. The test results showed that the baseline message, which used the tenant's accepted domain in the envelope sender, was rejected by Microsoft 365, while the bypassed message was classified as anonymous and unauthenticated.
The vulnerability has been observed in multiple phishing cases between September 2025 and August 2026, targeting executives, managers, finance staff, procurement teams, and customer-facing employees. Attackers commonly used document-sharing notices, payment requests, remittance details, procurement invitations, and voicemail or fax notifications as lures.