securityonline.info 9 Sept 2026, 07:10 UTC

Microsoft 365 Flaw Lets Spoofed Internal Emails Bypass Protection

Microsoft 365 Flaw Lets Spoofed Internal Emails Bypass Protection
CyberSIXT Evidence Panel Source marked as original reporting

RESEARCHERS have identified an active bypass of Microsoft 365’s RejectDirectSend control that enables spoofed internal emails to reach recipients. The flaw uses an empty SMTP envelope sender, allowing external senders to deliver unauthenticated messages that display internal company addresses in the From field.

In lab tests, a baseline message sent with a legitimate internal domain was blocked, but a second message sent with an empty envelope sender and a null reverse path bypassed the protection, with the visible From header still showing a familiar internal address.

The investigation attributes the activity to a range of threat actors and notes that the technique does not require stolen credentials or a compromised domain. The tactic has been used in targeted campaigns against senior executives, finance managers, and procurement staff between September 2025 and August 2026, with attackers circulating fake payment notifications, procurement requests, and meeting invites.

In some cases, messages bypassed standard authentication checks (SPF, DKIM, DMARC) yet were delivered due to permissive internal allow lists or other filtering gaps. The approach is described as simple and repeatable, encouraging ongoing use by multiple groups.

Defensive guidance emphasizes layered controls rather than blanket blocks on empty envelope senders. Recommended measures include IP-restricted inbound connectors for internal mail devices, auditing and removing broad allow-list exemptions (especially for executive addresses), and implementing transport rules to inspect headers for unresolvable hostnames and routing path mismatches. These steps aim to flag external messages that combine empty envelope senders with internal From domains, thereby neutralising the bypass.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline