A concerning Microsoft 365 feature known as Direct Send has become a favorite tool for attackers looking to bypass email authentication and impersonate organizations.
What is Direct Send?
Direct Send is a legitimate Microsoft 365 feature designed for:
- Internal applications sending automated emails
- Multifunction printers and scanners
- LOB (Line of Business) applications
- IoT devices sending notifications
How It's Supposed to Work
Direct Send allows applications to send email without authenticating by connecting directly to Microsoft's mail servers. It's intended for:
- Internal relay scenarios
- Devices that can't store credentials
- Legacy applications
The legitimate use case: Your office printer scans a document and emails it to you using your organization's domain, without needing a full mailbox license.
The Security Problem
The Exploit
Attackers discovered they could abuse Direct Send to:
- Send emails appearing to come from any Microsoft 365 domain
- Bypass SPF checks (because Microsoft's servers ARE authorized senders)
- Avoid DKIM failures (Direct Send emails often aren't DKIM-signed)
- Evade detection (emails originate from Microsoft infrastructure)
Why It Works
When an attacker sends via Direct Send:
- The email comes from Microsoft's IP addresses
- SPF passes because Microsoft is in most organizations' SPF records
- The "From" address can be spoofed to any domain using M365
- Recipients see a legitimate-looking email from a trusted organization
Real-World Attack Scenario
- Attacker creates a free Microsoft 365 trial
- Uses Direct Send to send email claiming to be from victim-company.com
- Email passes SPF because it's from Microsoft's infrastructure
- Recipient sees email from victim-company.com in their inbox
- Attacker uses this for phishing, BEC, or credential theft
Who Is Vulnerable?
Your organization is vulnerable if:
- You use Microsoft 365 for email
- Your SPF record includes Microsoft's servers (most M365 users)
- You don't have DMARC at enforcement (p=quarantine or p=reject)
- You don't have strict DKIM alignment requirements
Check Your Vulnerability
Use our free scanner to check:
- Is your SPF record including Microsoft servers?
- Do you have DMARC configured?
- Is your DMARC policy at enforcement level?
Protection Strategies
1. Implement DMARC with Enforcement
DMARC is the primary defense against Direct Send exploitation:
v=DMARC1; p=reject; rua=mailto:[email protected]
With p=reject, emails that fail DKIM alignment will be rejected, even if SPF passes.
2. Enable DKIM Signing
Ensure all legitimate email from your domain is DKIM-signed:
- Enable DKIM in Microsoft 365 Admin Center
- Configure DKIM for third-party senders
- Monitor DMARC reports for unsigned emails
3. Restrict Direct Send in Your Tenant
If you use Microsoft 365, restrict Direct Send:
- Exchange Admin Center → Mail Flow → Connectors
- Create an inbound connector restricting Direct Send to specific IPs
- Only allow known internal devices/applications
4. Enhanced Filtering for Connectors
Enable Enhanced Filtering for your connectors to preserve original sender information:
- Security Admin Center → Policies → Enhanced Filtering
- Enable for relevant connectors
- This helps detect spoofed Direct Send emails
Technical Deep Dive
How Direct Send Differs from SMTP Relay
| Feature | Direct Send | SMTP Relay |
|---|---|---|
| Authentication | None required | Credentials required |
| Sender restrictions | None | Authenticated sender |
| SPF behavior | Passes via Microsoft | Passes via Microsoft |
| DKIM | Usually not signed | Can be signed |
| Volume limits | 10,000/day | Higher limits |
Why SPF Alone Doesn't Protect You
SPF verifies that the sending server is authorized, not the From address. When Microsoft sends on someone's behalf:
- Email comes from Microsoft's servers
- SPF checks Microsoft's IP → Pass
- From address could be any domain → Not checked by SPF
This is exactly why DMARC alignment is critical.
Microsoft's Response
Microsoft has acknowledged the issue and recommends:
- Using authenticated SMTP submission where possible
- Implementing DMARC with enforcement
- Restricting Direct Send via connector rules
- Monitoring for abuse in audit logs
However, they haven't disabled Direct Send due to legitimate business use cases.
Action Items
Immediate (Today)
- Scan your domain to check current authentication status
- Review your SPF record for Microsoft inclusion
- Check if DMARC is at enforcement level
Short-Term (This Week)
- Enable DKIM signing in Microsoft 365
- Create DMARC record if missing
- Move DMARC to p=quarantine if currently at p=none
Medium-Term (This Month)
- Review Direct Send usage in your tenant
- Create connector rules to restrict unauthorized Direct Send
- Move DMARC to p=reject after monitoring
Don't let a legitimate feature become your security vulnerability.
Check your Microsoft 365 configuration now or contact us for help securing your email infrastructure.
Related Topics
Ready to Secure Your Email?
Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.