Researchers find a hole in Microsoft's anti-spoofing fix

Microsoft Ahead Of Earnings Figures
David Paul Morris/Bloomberg
  • Key insight: A message sent with an empty return address gets accepted by Microsoft 365 tenants that have Reject Direct Send switched on, while an otherwise identical message gets turned away.
  • What's at stake: The technique requires no stolen password, no compromised account and no answered multi-factor prompt, so defenses built around protecting logins do not address it.
  • Forward look: ReliaQuest expects attackers to keep using the technique and to spend their effort on getting messages out of the junk folder, while Microsoft says it is working on an option to disable Direct Send by default.

Overview bullets generated by AI with editorial review.

Processing Content

Microsoft released a setting last year that blocks external emails that disguise themselves as internal. Researchers showed last week that a small workaround gets threat actors past it.

The setting, Reject Direct Send, governs a Microsoft 365 feature called Direct Send, which lets printers, scanners and other equipment drop mail into a company's system without logging in. Attackers abused that to make external email look internal, which is why Microsoft built the setting.

Attackers who send a message to a company that has enabled Reject Direct Send can get their message into the target mailbox simply by leaving the return address (a field the recipient never sees) empty, according to research the security firm ReliaQuest published Thursday.

One of the primary risks here is business email compromise — the fraud in which an employee gets talked into wiring money or handing over credentials. These schemes often start with an email that appears to come from IT or a company executive.

With the Reject Direct Send workaround, an outsider can deliver a message to the target mailbox without any kind of password, multifactor authentication bypass or network compromise.

The finding comes after the FBI in May described a phishing kit that hijacks the same Microsoft 365 mailboxes bank staff use for work. That kit needs a stolen login session; this one does not.

Microsoft did not immediately respond to a request for comment.

The National Credit Union Administration told credit unions to shut down this kind of spoofing nearly five years ago. A 2021 risk alert from the agency told them to enable "security features that block malicious email, such as anti-phishing and anti-spoofing policies."

Why these emails don't go to junk

In some of the cases ReliaQuest described, spoof messages landed in the junk folder rather than the inbox. However, most of them reached the target inbox.

One way messages reached the inbox was through exception lists; these are overrides administrators configure so that mail from an approved sender skips the spam filter.

That means a smart, targeted enough spoof email just has to impersonate the right person to reach the target.

In one such case ReliaQuest described, a message failed every sender authentication check, and Microsoft's filtering even classified it as phishing. Yet, it landed in the target inbox anyway because an approved-sender list included the executive the spoof email impersonated.

ReliaQuest said it was calling out a limit on the scope of the Reject Direct Send feature, not a flaw in Microsoft's software. Indeed, Microsoft itself acknowledged this kind of limitation when it announced Reject Direct Send in April 2025.

Microsoft explained at the time that the setting evaluates the return address on the envelope, not the sender address a reader actually sees.

On whether customers need to use Reject Direct Send to consider themselves protected, Microsoft answered in an FAQ: "No." The setting "joins many layers of protection in Microsoft 365," the post said.

Microsoft's product documentation says most customers do not need Direct Send in the first place. It recommends it only for legacy equipment and says the company is working on an option to disable Direct Send by default.

How to defend

ReliaQuest sells detection software, and some of its recommendations point toward its own products. Others a company such as a bank can implement on its own:

One defense stopped every attempt ReliaQuest tried: a restricted inbound connector (a filter that accepts mail only from approved machines) blocked spoof emails no matter what their envelope said.

ReliaQuest also said in its report that institutions that already restrict which machines can deliver mail are not exposed.

For everyone else, ReliaQuest recommends reviewing every spam override the company has configured, noting which entries cover an executive or a manager and deleting the ones the company cannot justify. This reduces the number of people a threat actor can successfully impersonate.

ReliaQuest said it expects attackers to keep using the technique and to spend their effort on getting messages out of the junk folder.


For reprint and licensing requests for this article, click here.
Cyber Security Credit unions Data security Cyber attacks Microsoft Technology
MORE FROM NATIONAL MORTGAGE NEWS
Load More