Skip to content

Microsoft 365 Direct Send Bypass Lets Attackers Spoof Internal Users Without Credentials

Gbhackers Mayura Kathir September 4, 2026

A Microsoft 365 email security-control bypass that lets attackers submit unauthenticated messages posing as internal users by leaving one SMTP field blank. The technique targets Exchange Online’s RejectDirectSend setting and does not represent a vulnerability in Microsoft software or in ReliaQuest systems; instead, it exposes a limitation in how the control evaluates Direct Send traffic. […]

Extracted Entities

Attack Types (1)

MITRE ATT&CK (1)