Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Microsoft Exchange Online Outage Delays External Emails
September 4, 2026
Microsoft 365 Phishing Evades Blocking With Empty Sender Technique
September 4, 2026
OpenAI Agents Hijack German Wiki to Share Evasion Tactics
September 4, 2026
Home/CyberSecurity News/Microsoft 365 Phishing Evades Blocking With Empty Sender Technique
CyberSecurity News

Microsoft 365 Phishing Evades Blocking With Empty Sender Technique

Key Takeaways A novel phishing technique targets Microsoft 365 users by exploiting a loophole in Exchange Online’s Direct Send control. Attackers leave the SMTP envelope sender blank, allowing...

David kimber
David kimber
September 4, 2026 4 Min Read
2 0

Key Takeaways

  • A novel phishing technique targets Microsoft 365 users by exploiting a loophole in Exchange Online’s Direct Send control.
  • Attackers leave the SMTP envelope sender blank, allowing unauthenticated messages to bypass security measures while displaying a seemingly legitimate internal “From” address.
  • This method enables highly convincing impersonation emails, increasing the risk of credential theft, malware delivery, and fraudulent transactions.
  • The issue is not a software vulnerability but an exploitation of how the “RejectDirectSend” control evaluates incoming mail.
  • Reliaquest researchers discovered the technique and recommend implementing IP-restricted inbound connectors and reviewing mail flow rules.

A sophisticated phishing technique is actively circumventing Microsoft 365’s email security protocols, enabling attackers to send highly convincing spoofed emails to unsuspecting users. This method leverages a subtle modification: leaving the SMTP envelope sender address blank. This seemingly minor alteration allows unauthenticated messages to bypass the “RejectDirectSend” safeguard in Exchange Online, presenting recipients with an email that appears to originate from within their own organization.

Table Of Content

  • Key Takeaways
  • Microsoft 365 Phishing Technique Uses Empty Envelope Sender
  • Targeting and Defensive Steps
  • What You Should Do

This approach is not indicative of a software vulnerability within Microsoft’s products, nor does it necessitate the compromise of an existing user account. Instead, it exploits a specific characteristic of how Exchange Online’s “RejectDirectSend” control operates. The system primarily scrutinizes the domain specified in the envelope sender, rather than the “From” address that is visibly displayed to the recipient. This critical distinction provides a straightforward pathway for malicious actors to conduct successful impersonation campaigns, effectively neutralizing a security barrier designed to prevent a particularly dangerous form of email spoofing.

Researchers at Reliaquest first identified this pattern in ongoing phishing campaigns and successfully replicated it within a controlled Microsoft 365 tenant. According to Reliaquest said in a report, the technique has been observed consistently across various unrelated organizations over the past year. Such deceptive internal-looking emails often contain lures like document notifications, payment requests, or voicemail prompts. Even if some messages are flagged by mail filters, any email that successfully reaches a recipient’s inbox poses a significant threat, potentially leading to credential harvesting, malware infections, fraudulent financial transfers, and broader account compromise.

Microsoft 365 Phishing Technique Uses Empty Envelope Sender

The “Direct Send” feature in Microsoft 365 is designed to allow devices and applications to send emails within the same tenant without requiring explicit authentication. Previous analyses of Microsoft 365 Direct Send have highlighted instances where attackers could impersonate internal users without needing to compromise their accounts.

The “RejectDirectSend” control is specifically engineered to block unauthenticated Direct Send emails that falsely claim to originate from an organization’s accepted domain. Reliaquest conducted tests by sending two messages to a tenant’s mail host. A message using the tenant’s domain in its envelope sender was correctly rejected. However, a message utilizing the SMTP command MAIL FROM: (an empty envelope sender) was accepted and queued for delivery.

Crucially, the recipient still saw the same internal IT support address in the visible “From” field. Because the empty sender field contains no domain, “RejectDirectSend” has no domain to compare against the tenant’s list of accepted domains. Consequently, the control fails to apply its rejection condition, even though the message originated from an unauthenticated external source.

While acceptance into the mail flow does not guarantee inbox delivery, it significantly increases risk. During Reliaquest’s tests, the anonymous test message was marked with a Spam Confidence Level (SCL) of 9 and routed to Junk Email after SPF and DKIM authentication failed, and DMARC also returned no result. Nevertheless, email filtering outcomes can vary widely based on content, infrastructure, specific configurations, and pre-existing trusted-sender exceptions. In one documented instance, a message that failed all sender-authentication checks, despite being classified as high-confidence phishing, still reached an inbox because the spoofed executive was listed as an “allowed sender.” Organizations are therefore advised to review their email authentication configuration guidance and eliminate any exceptions that could override these crucial security checks.

Targeting and Defensive Steps

ReliaQuest’s analysis of phishing attempts between September 2025 and August 2026 revealed that attackers predominantly targeted high-value individuals and roles. These included executives, managers, finance personnel, procurement teams, and customer-facing employees. These roles are frequently involved in handling sensitive documents such as invoices, bids, shared files, and payment instructions, making them susceptible to convincing business-themed lures.

Common phishing themes included file-sharing notifications, payment and remittance requests, procurement invitations, loan or investment offers, and meeting invitations. Some attacks incorporated SVG attachments disguised as voicemail recordings. This tactic mirrors previously observed weaponized SVG phishing files, which can redirect users to malicious sites rather than simply displaying an image. While “RejectDirectSend” remains a valuable control, security teams should not consider it a comprehensive defense. Implementing an IP-restricted inbound connector can significantly enhance security by permitting unauthenticated Direct Send only from explicitly approved devices and applications. This measure has been shown to block all Direct Send attempts, even those with a blank envelope sender.

What You Should Do

  • Implement IP-Restricted Inbound Connectors: Identify all systems that genuinely require Direct Send capabilities and configure IP-restricted inbound connectors to permit unauthenticated Direct Send only from these specific, approved source IP addresses.
  • Review and Remove Unjustified Filtering Exceptions: Scrutinize all existing mail flow rules and filtering exceptions, including allowed senders, allowed domains, safe-sender entries, and rules that modify spam scores. Eliminate any exceptions that are not absolutely essential and justified.
  • Search for Anomalous Email Headers: Actively monitor and search for emails combining an empty envelope sender (MAIL FROM:) with a visible “From” address belonging to an accepted internal domain. This pattern is distinct from legitimate bounce messages. Prioritize investigation of alerts where SPF, DKIM, or DMARC authentication also failed, but the message was delivered due to an override.
  • Enhance Employee Awareness Training: Educate employees to independently verify any unexpected requests for payments, documents, or access via a known, trusted communication channel (e.g., a phone call to a verified number) before responding to the email or opening any attachments.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackExploitMalwarephishingSecurity

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

OpenAI Agents Hijack German Wiki to Share Evasion Tactics

Next Post

Microsoft Exchange Online Outage Delays External Emails

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Trezor Confirms ShipMonk Breach Exposed 67,000 US Customers
September 4, 2026
Microsoft Teams to Block Malicious QR Codes in Messaging
September 4, 2026
North Korean Hackers Use Fake macOS Installers to Deliver RAT
September 4, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us