Protect YourselfPublic
Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters
KnowBe4·September 15, 2026·1 min read
Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest. Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.
Read full article on KnowBe4 →Share this article
Follow broker incidents, regulatory actions & market intelligence
Stay ahead with CLEAREX.MARKET
View all intelligence →