Microsoft 365 users are encountering a novel phishing method that exploits a specific loophole: attackers are crafting emails with an empty SMTP envelope sender. This tactic can enable unauthenticated messages to slip past Direct Send protections, while presenting email addresses that appear legitimate to employees.
Understanding the Technique
This method does not stem from a flaw in Microsoft software nor does it require compromised accounts. The technique takes advantage of how Exchange Online’s RejectDirectSend feature examines the domain in the SMTP envelope sender, rather than the visible From field address. This discrepancy allows cybercriminals to easily impersonate internal communications, bypassing a safeguard meant to block dangerous email spoofing.
Researchers at ReliaQuest uncovered this pattern in active phishing incidents and successfully replicated it within a controlled Microsoft 365 environment. According to their report, this strategy has been used across various organizations over the past year, often masquerading as internal messages such as document notices, payment requests, or voicemail alerts.
Implications for Security
While some phishing attempts might be caught by mail filters, any message that reaches its target can facilitate credential theft, malware dissemination, unauthorized financial transactions, and broader account breaches. The Direct Send feature permits devices and applications to send emails within the same Microsoft 365 tenant without needing authentication, which attackers have exploited to mimic internal users without account compromise.
In testing, ReliaQuest observed that messages with the tenant’s domain in the envelope sender were rejected, yet those using an empty sender field were accepted and processed. Although flagged as spam with a high Spam Confidence Level, such messages can occasionally land in inboxes under certain configurations.
Defensive Measures
ReliaQuest’s analysis of phishing targets from late 2025 to mid-2026 revealed a focus on executives, managers, financial personnel, and customer service roles, often engaging in tasks like handling invoices and payment instructions. Common phishing lures included file-sharing alerts, payment requests, procurement invitations, and meeting notices, sometimes utilizing SVG attachments to mimic voicemail.
To bolster defenses, organizations should maintain the RejectDirectSend feature while implementing an IP-restricted inbound connector to only allow unauthenticated Direct Send from verified devices and applications. It is also crucial to eliminate unnecessary filtering exceptions and scrutinize trusted routes and permissive rules.
Furthermore, administrators should monitor for emails with empty envelope senders paired with visible From addresses mimicking internal domains, especially when standard email authentication checks fail but delivery occurs through exceptions. Employees must verify unexpected requests for payments or documents through known communication channels before proceeding.
Staying informed about emerging malware and phishing tactics is vital. Security teams should ensure they are updated on threats within 24 hours of their emergence.
