Microsoft 365 Email Controls Bypassed by Attackers
A security vulnerability in Microsoft 365 email controls has been discovered by ReliaQuest. The company found that attackers can bypass RejectDirectSend, a control designed to block unauthenticated Direct Send emails from using an organisation's own domain. This is done by leaving the SMTP envelope sender blank.
This allows external senders to omit the envelope domain while still showing an internal-looking address in the visible From field. This makes phishing messages appear more trustworthy, especially when they seem to come from familiar business contacts such as executives or support teams.
ReliaQuest identified numerous examples of this vulnerability over the past year, with attackers often using self-addressed messages and routine business themes to target high-value users in finance-related roles. Document-sharing alerts and file notifications were common lures, followed by payment requests and loan offers.