Empty SMTP Sender Can Bypass Microsoft 365 RejectDirectSend Control

· Original article ↗

Summary

ReliaQuest found that an unauthenticated email with an empty SMTP envelope sender can bypass Microsoft 365’s RejectDirectSend control while displaying an internal-looking From address. IP-restricted inbound connectors blocked the attempts in testing.

Key points

  • RejectDirectSend checks the SMTP envelope sender’s domain; an empty sender leaves no domain to check, allowing Microsoft 365 to accept and queue the message.
  • In controlled testing, the baseline message was rejected, while the otherwise similar message with MAIL FROM:<> was accepted. Acceptance did not guarantee inbox delivery: one test message went to Junk Email.
  • ReliaQuest observed the empty-envelope pattern in phishing cases across multiple organizations between September 2025 and August 2026. RejectDirectSend was confirmed enabled in only one tenant.
  • Messages used internal-looking sender addresses and commonly targeted leadership and business-facing roles with file-sharing, payment, procurement, and other business-themed lures.
  • IP-restricted inbound connectors blocked all tested Direct Send attempts, regardless of envelope sender.
  • ReliaQuest recommends limiting Direct Send to approved source IPs, reviewing mail-filtering exceptions, and monitoring for empty envelope senders paired with internal From addresses and failed authentication.

Article Details

Attack Vectors
  • An external sender can submit unauthenticated Direct Send mail with an empty SMTP envelope sender (MAIL FROM:<>) while placing an internal-looking address in the visible From header. ReliaQuest testing showed that this bypassed RejectDirectSend's envelope-domain check, although it did not guarantee inbox delivery.
  • In investigated phishing cases, attackers repeatedly used self-addressed messages and business-themed lures targeting leadership and business-facing users. Several messages carried SVG attachments presented as voicemail recordings.
  • In one investigated case, a message classified as high-confidence phishing reached an inbox because the spoofed executive address was listed as an allowed sender. RejectDirectSend enablement was confirmed for only one of the tenants in the investigated cases.
Defensive Notes
  • Use IP-restricted inbound connectors to allow Direct Send only from approved source IP addresses. In ReliaQuest's test, such a connector blocked every Direct Send attempt regardless of envelope sender.
  • Keep RejectDirectSend enabled, but do not rely on it alone to prevent internal sender impersonation.
  • Review and remove unjustified filtering exceptions, particularly allowed senders or domains covering executives and managers.
  • Monitor for an empty envelope sender combined with an internal From address, especially when sender authentication fails but a filtering override permits delivery. Legitimate bounce messages can also have empty envelope senders.

MITRE ATT&CK

People

Vendors

Products

Related Articles