CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

One Blank Field Bypasses Direct Send Control

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5640

As cited

Copy frozen at (site build).

threat intel

One Blank Field Bypasses Direct Send Control

ReliaQuest researchers discovered that an empty Simple Mail Transfer Protocol (SMTP) envelope sender bypasses Microsoft 365's RejectDirectSend control, which blocks unauthenticated Direct Send emails claiming an organization's domain. The bypass allows phishing messages to display legitimate-looking internal addresses while avoiding the control's domain-based rejection logic. Active phishing campaigns between September 2025 and August 2026 exploited this technique primarily against leadership and finance roles using file-sharing and payment-request lures.

Why it matters: Organizations relying solely on RejectDirectSend to prevent internal email impersonation face continued exposure to spearphishing that reaches inboxes despite the control being enabled. Security teams should implement IP-restricted inbound connectors, remove unnecessary filtering exceptions covering privileged users, and monitor for the empty-envelope-plus-internal-address pattern to block further attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

One Blank Field Bypasses Direct Send Control

ReliaQuest researchers discovered that an empty Simple Mail Transfer Protocol (SMTP) envelope sender bypasses Microsoft 365's RejectDirectSend control, which blocks unauthenticated Direct Send emails claiming an organization's domain. The bypass allows phishing messages to display legitimate-looking internal addresses while avoiding the control's domain-based rejection logic. Active phishing campaigns between September 2025 and August 2026 exploited this technique primarily against leadership and finance roles using file-sharing and payment-request lures.

Why it matters: Organizations relying solely on RejectDirectSend to prevent internal email impersonation face continued exposure to spearphishing that reaches inboxes despite the control being enabled. Security teams should implement IP-restricted inbound connectors, remove unnecessary filtering exceptions covering privileged users, and monitor for the empty-envelope-plus-internal-address pattern to block further attacks.

VendorsMicrosoft
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary