Attackers are abusing Microsoft 365 Direct Send by submitting phishing emails with an empty SMTP envelope sender (MAIL FROM:<>) while placing a spoofed internal address in the visible From field. This bypasses the domain-comparison condition used by Exchange Online's RejectDirectSend control, enabling convincing internal-impersonation messages without a compromised Microsoft 365 account or a software vulnerability. ReliaQuest observed the technique across unrelated organizations and reproduced it in a controlled tenant.
Microsoft 365 authentication and filtering controls can still classify the messages as anonymous, high-confidence spam, or phishing because SPF, DKIM, and DMARC checks fail. However, permissive allowed-sender lists and other mail-filtering exceptions can cause delivery to user inboxes. Organizations should limit Direct Send through IP-restricted inbound connectors, remove unnecessary filtering overrides, and monitor for empty envelope senders combined with internal-looking From addresses, authentication failures, and override-assisted delivery.

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Between September 2025 and August 2026, ReliaQuest examined phishing activity targeting personnel including executives, finance staff, procurement teams, and customer-facing employees. Attackers used `MAIL FROM:<>` with spoofed internal visible From addresses to evade Exchange Online RejectDirectSend's envelope-domain comparison; file-sharing notices were the most common lure.
ReliaQuest reproduced the technique in a controlled Microsoft 365 tenant: a message using the tenant domain in its envelope sender was rejected, while one using `MAIL FROM:<>` was accepted and queued with the same spoofed internal IT-support visible From address. Microsoft 365 marked the accepted test message anonymous with an SCL of 9 and routed it to Junk Email; an IP-restricted inbound connector blocked Direct Send attempts including empty-envelope messages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcecryptika.com
Open sourcereliaquest.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.