As cited
Copy frozen at (site build).
threat intel
One Blank Field Bypasses Direct Send Control
ReliaQuest researchers discovered that an empty Simple Mail Transfer Protocol (SMTP) envelope sender bypasses Microsoft 365's RejectDirectSend control, which blocks unauthenticated Direct Send emails claiming an organization's domain. The bypass allows phishing messages to display legitimate-looking internal addresses while avoiding the control's domain-based rejection logic. Active phishing campaigns between September 2025 and August 2026 exploited this technique primarily against leadership and finance roles using file-sharing and payment-request lures.
Why it matters: Organizations relying solely on RejectDirectSend to prevent internal email impersonation face continued exposure to spearphishing that reaches inboxes despite the control being enabled. Security teams should implement IP-restricted inbound connectors, remove unnecessary filtering exceptions covering privileged users, and monitor for the empty-envelope-plus-internal-address pattern to block further attacks.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
One Blank Field Bypasses Direct Send Control
ReliaQuest researchers discovered that an empty Simple Mail Transfer Protocol (SMTP) envelope sender bypasses Microsoft 365's RejectDirectSend control, which blocks unauthenticated Direct Send emails claiming an organization's domain. The bypass allows phishing messages to display legitimate-looking internal addresses while avoiding the control's domain-based rejection logic. Active phishing campaigns between September 2025 and August 2026 exploited this technique primarily against leadership and finance roles using file-sharing and payment-request lures.
Why it matters: Organizations relying solely on RejectDirectSend to prevent internal email impersonation face continued exposure to spearphishing that reaches inboxes despite the control being enabled. Security teams should implement IP-restricted inbound connectors, remove unnecessary filtering exceptions covering privileged users, and monitor for the empty-envelope-plus-internal-address pattern to block further attacks.
- Source published
- First seen by Cybersecurity Tracker