Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters
Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.
Microsoft 365 Exchange Online uses a feature called βRejectDirectSendβ to block unauthenticated Direct Send emails from an organizationβs trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.