Security1 distinct publisher2 min readPublished
ReliaQuest's tests show Exchange Online accepts unauthenticated mail when the visible From header matches the tenant domain and the SMTP envelope sender is left empty. Forty percent of those messages went to senior leaders.
The Watch · Security desk
Follow any of these and your For You feed starts watching them — no settings page required.
security
Microsoft implicates its own anti-spam protections in Exchange Online's external mail delays1 distinct publisher
security
SVG attachments mislabelled as plain text carried JavaScript into 5,527 organizations2 distinct publishers
security
Microsoft retracts its root-cause explanation for Teams Mac call failures1 distinct publisher
product
Outlook's Monday outage left one user unable to receive verification emails, others reporting varied issues1 distinct publisher
Compiled by The WatchSomething wrong?How this is made
RejectDirectSend does what its name says and no more. It rejects unauthenticated mail whose SMTP envelope sender claims the tenant's own domain [2]. An empty envelope claims nothing, so there is nothing to match, and Exchange Online accepts and queues the message while the visible From header still reads as internal [1][3]. ReliaQuest frames this as a byproduct of how Exchange Online and Microsoft 365 handle mail, rather than a flaw in either product: empty envelope senders are how non-delivery reports get sent, and dropping them all would break legitimate mail [4].
So the gap sits in tenant configuration. The one control that held in ReliaQuest's tests was a secure email gateway fronted by IP-restricted inbound connectors, which blocked every attempt to deliver unauthenticated mail with a blank envelope sender [5]. ReliaQuest's other two recommendations govern what happens after acceptance: strip mail-filtering exceptions that let internal-looking mail skip inspection, and alert on the combination of an empty envelope sender and an internal From address [6]. Acceptance and delivery are different steps, and ReliaQuest notes spam filtering can still push these messages to junk [7].
Between September 2025 and August 2026, 40 percent of the empty-envelope, domain-spoofing phishing ReliaQuest counted went to senior leaders, 25 percent to managers and sales staff, 20 percent to individual contributors and 15 percent to shared or service mailboxes [8]. Executives took twice the volume individual contributors did [9], and about two-thirds of the total landed on leadership, management or sales [10]. Lures led with document and file-sharing notifications, followed by payment requests, procurement invitations, loan and investment offers and meeting invitations; some carried SVG attachments dressed up as voicemail recordings [11].
The evidence stops short of attribution. ReliaQuest describes several phishing campaigns over the past year using the technique [12], and stops there: no named actor, no losses, and no count of how many tenants switched RejectDirectSend on or when. Anyone reading this as a broken security feature is reading past ReliaQuest's own framing.
The technique needs no credentials, no compromised domain and no dedicated infrastructure, which is why ReliaQuest expects it to keep running for another six to twelve months [13].
Ranked by verification strength, evidence, and original report placement.
Between September 2025 and August 2026, ReliaQuest found that 40% of phishing emails sent with an empty envelope and a spoofed From header impersonating the victim's domain went to senior leaders, 25% to managers and sales employees, 20% to individual contributors and 15% to shared or service mailboxes.
ReliaQuest reported on a Thursday that attackers are targeting senior leaders with phishing emails using an 'empty envelope' technique that bypasses Microsoft 365's RejectDirectSend protection for Exchange Online.
RejectDirectSend is intended to prevent abuse of Direct Send, which allows unauthenticated email to be sent from internal organizational domains, typically for IoT devices and applications such as printers that cannot safely store credentials. Unauthenticated emails whose SMTP envelope matches the organization's domain are blocked by RejectDirectSend.
ReliaQuest found in its tests that unauthenticated emails appearing to come from an internal domain still reach inboxes when the visible From header matches the internal domain but the SMTP envelope sender is left blank; such 'empty envelope' emails are accepted and queued.
ReliaQuest noted this is not a vulnerability in Exchange Online or Microsoft 365, because empty envelope emails are also sent legitimately for purposes such as non-delivery reports, and blocking them completely could disrupt legitimate email activity.
ReliaQuest found that using a secure email gateway with IP-restricted inbound connectors blocked all tested attempts to send unauthenticated emails with a blank SMTP envelope sender.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 4, 2026
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One vendor's tests, relayed once
Everything traces back to ReliaQuest's lab work and ReliaQuest's telemetry, passed along by SC World without a Microsoft response or a second researcher confirming that a blank envelope sender clears RejectDirectSend. The mechanism itself is described precisely enough for an administrator to reproduce in a test tenant, which is what holds the score up. The counting is weaker: a four-way recipient split arrives with no message total, no tenant count and no description of how the sample was assembled.
Live campaigns, undisclosed volume
The abuse is presented as observed rather than hypothetical: several campaigns in the past year, and a full twelve months of collected messages sorted by recipient seniority. Scale is the missing half. Shares of an undisclosed total describe who is being aimed at without saying how much of this traffic exists, and no other firm has published matching sightings for the technique.
Caveated throughout, one loose number
Most of the restraint comes from the vendor. ReliaQuest says plainly that this is not an Exchange Online flaw and that clearing RejectDirectSend still leaves spam filtering in the way, and SC World keeps both statements. The framing outruns the evidence in one place only, and it is the place readers remember: the 40% figure travels into headline and standfirst with the firmness of an audited statistic while resting on a sample nobody outside ReliaQuest has seen.
Research that sells its own remedy
ReliaQuest sells managed detection, and the fix list reads accordingly: a secure email gateway, tightened inbound connectors, and an alert rule of exactly the kind a monitoring service supplies. That does not make the test result wrong, since IP-restricted connectors blocking blank-envelope mail is checkable in any tenant. It does mean the research and the products behind it point the same way, and SC World runs the recommendations without a countervailing voice or a note on who benefits.
Verifiable mechanism, opaque sample
The split is unusually clean here. An administrator can settle the header-and-envelope claim in an afternoon, whereas the numbers that make the story worth reading cannot be settled at all from what has been published. One outlet, one vendor, no reply from Microsoft, and a forecast that rests on the researchers' judgement alone.