Hackers Bypass Microsoft 365 RejectDirectSend With Empty SMTP Sender to Spoof Internal Emails
Brief
Threat actors can bypass Microsoft 365’s RejectDirectSend protection by using an empty SMTP envelope sender, allowing phishing messages to appear as if they were sent by trusted internal users, according to ReliaQuest.
RejectDirectSend is an Exchange Online control designed to stop unauthenticated Direct Send emails that claim to originate from an organization’s own Microsoft 365 domain .
Direct Send is commonly used by printers, scanners, applications, and other devices to send messages to users within the same tenant without needing sign-in credentials.
However, ReliaQuest found that the control checks the domain in the SMTP envelope sender, also called the MAIL FROM address.
When attackers send a message using an empty envelope sender, represented as MAIL FROM: , there is no domain available for RejectDirectSend to evaluate.
