Vulnerability in Microsoft's Anti-Spoofing Fix Allows Spoofed Emails to Reach Inboxes
Researchers at ReliaQuest discovered a vulnerability in Microsoft's anti-spoofing fix, Reject Direct Send. The feature is designed to block external emails that disguise themselves as internal. However, by leaving the return address empty, attackers can bypass this security measure and send spoofed messages to target mailboxes.
This technique requires no stolen password, compromised account, or answered multi-factor prompt, making it difficult for defenses built around login protection to address. The finding comes after the FBI described a phishing kit that hijacks Microsoft 365 mailboxes used by bank staff in May.
Microsoft's Reject Direct Send setting evaluates the return address on the envelope, not the sender address visible to readers. This limitation allows spoofed messages to reach the inbox even if they fail all other authentication checks. In fact, a message that was classified as phishing still landed in the target inbox because it impersonated an executive whose email address was on an approved-sender list.
ReliaQuest expects attackers to continue using this technique and focus their efforts on getting messages out of the junk folder. Microsoft is working on an option to disable Direct Send by default, but for now, institutions can implement a restricted inbound connector or review spam override configurations to prevent spoofed emails from reaching the inbox.