Microsoft 365 Phishing Technique Evades Direct Send Blocking
Microsoft 365 users are being targeted by a new phishing technique that exploits a loophole in the service's Direct Send feature. By leaving the SMTP envelope sender blank, attackers can evade direct send blocking and appear to be sending emails from within the organization.
This approach takes advantage of how Exchange Online's RejectDirectSend control checks the domain in the envelope sender, rather than the address displayed in the visible From field. This difference allows criminals to impersonate internal users without compromising an account or exploiting a software flaw.
Researchers at ReliaQuest identified this pattern in active phishing cases and reproduced it in a controlled Microsoft 365 tenant. They found that a convincing internal-looking email can carry a document notice, payment request, or voicemail lure, potentially leading to credential theft, malware delivery, and account compromise.