Microsoft 365 Email Bypass Technique Exposes Organisations to Phishing Attacks
A recent investigation by ReliaQuest has uncovered a vulnerability in Microsoft 365's email control system that allows attackers to bypass authentication checks. The technique, which has been observed repeatedly in phishing investigations across multiple organisations, relies on leaving the SMTP envelope sender blank.
The RejectDirectSend control, designed to block unauthenticated Direct Send emails using an organisation's own domain, checks the domain in the SMTP envelope sender. However, when this field is left empty, it provides no domain for evaluation, allowing external senders to disguise their messages as internal communications.
ReliaQuest tested this vulnerability by comparing two unauthenticated messages sent directly to a Microsoft 365 tenant. One message included an envelope sender with the accepted domain, while the other used an empty sender. The results showed that the second message was accepted and queued, despite failing authentication checks.
The organisation identified numerous examples of this technique being used in phishing attacks over the past year, often targeting executives, managers, and users in customer-facing or finance-related roles. These messages typically used self-addressed themes and routine business topics to trick users into opening attachments, clicking links, or acting on financial requests.