Researchers at InfoGuard disclosed Ghost-Sender, an email spoofing weakness affecting Microsoft Exchange Online and hybrid Exchange deployments that use a third-party mail server, secure email gateway, or spam filter as the public MX record. In vulnerable setups, attackers can send messages directly to the tenant’s Exchange Online Protection endpoint and make them appear to come from any internal or external sender, while bypassing SPF, DKIM, and DMARC checks and often landing in users’ inboxes without meaningful warning. InfoGuard said the issue is simple to exploit, observed that more than 20% of scanned bug bounty domains using Exchange Online appeared vulnerable, and noted that spoofed internal messages can even display Outlook profile photos, increasing their credibility.
The researchers said Microsoft’s standard protection settings, dashboards, and configuration analyzers do not clearly identify or prevent the exposure, and described a disputed disclosure process in which MSRC reportedly treated the issue as an architectural limitation rather than a security vulnerability. InfoGuard cited Microsoft support communications indicating active and widespread abuse beginning in April, and published mitigations for affected organizations: configure a wildcard Partner Organization connector restricted by approved IP addresses or certificates, add a priority-0 mail flow rule to quarantine messages that do not originate from trusted infrastructure or lack the expected internal authentication header, and disable Direct Send to reduce internal spoofing risk, though that step does not stop spoofing of arbitrary external senders.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
InfoGuard disclosed the "Ghost-Sender" issue affecting Exchange Online and hybrid/on-premises Exchange setups with external MX or third-party mail filtering, describing how attackers can spoof arbitrary senders and bypass SPF, DKIM, and DMARC checks. The researchers also published technical details, a testing tool, and recommended mitigations including partner connectors and mail flow rules.
According to InfoGuard's disclosure timeline, Microsoft support acknowledged active widespread abuse of the Exchange spoofing issue or a related problem beginning on 2026-04-21.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
labs.infoguard.ch
Open sourcedarkreading.com
Open sourceghost-sender.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.