Skip to content

Security1 publisher2 min readPublished

Direct Send carried 29,785 spoofed internal emails past the mail gateway in two months

KnowBe4's Threat Lab logged the messages across July and August 2026. None of them needed a stolen password to look like mail from HR or accounting, and a single send addressed 900 recipients. The report landed September 10.

The Watch · Security desk

Illustration accompanying Direct Send carried 29,785 spoofed internal emails past the mail gateway in two months

What happened

  • KnowBe4's Threat Lab counted 29,785 confirmed phishing emails abusing Microsoft 365's Direct Send feature across July and August 2026, in a report published September 10.
  • Direct Send exists so printers, scanners and legacy applications can send mail without a dedicated account, and the operators used it to make messages look like they came from HR, accounting or admin.
  • The messages reached mailboxes by connecting straight to the tenant's Exchange Online MX endpoint, bypassing the organisation's email security gateway with no employee credentials involved.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability Spoofing an internal sender here takes no phished password and no malware, only the ability to reach the tenant's MX record.
  • constraint A gateway cannot inspect mail that never passes through it, so enforcement moves to Exchange Online connectors and domain authentication.
  • decision Switching DMARC from p = none to p = reject bounces unsigned mail claiming the domain. The inventory of printers, scanners and legacy senders has to be finished before that switch, not after it.
  • exposure Where the reply-to points off-domain, the victim's own reply becomes the channel, and the loss lands in accounts payable.

The bypass is a routing fact. Direct Send delivers to the tenant's own Exchange Online MX endpoint, so mail sent that way never transits the security gateway in front of the mailboxes [6]. Rules written at that gateway never see the message. There is nothing in the sign-in logs either, because the sender never authenticates as anyone: the feature exists so printers, scanners and legacy applications can send mail without a dedicated account [3][5].

That leaves domain authentication as the only control in the path, and a monitoring-only posture does not hold. "While authentication checks may detect that something is wrong, organizations using a domain-based message authentication, reporting and conformance (DMARC) monitoring policy can still allow the message to be delivered," KnowBe4's report said [7]. Its remedy is p = reject in place of p = none [15].

Attachments rode about 10,400 of the messages, which is 35% of 29,785, and KnowBe4 classified virtually all of them as threats [8][1]. Another 4,023 carried a reply-to address on a different domain, 13.5% of the total, routing employee responses to the operator [10][2]. One send addressed 900 recipients [11].

Across a 62-day window, 29,785 messages average roughly 480 a day [3]. KnowBe4 did not see them spread evenly: activity clustered Monday to Tuesday inside US Eastern business hours, peaking just before noon, dipping, then reaching its daily high near 2pm EST [12]. The researchers called this a "distinctly human pattern" [13]. It tells you when the sending was scheduled, not where the operators sit, and the report names no group [18].

For hunting, the marker is the header X-MS-Exchange-Organization-AuthAs: Anonymous, which indicates an unauthenticated delivery path [14]. The rest of KnowBe4's list is inventory work: restrict senders through Exchange Online connectors to approved IP addresses, sign outbound mail with DKIM so DMARC has something to check, and close the Direct Send pathway where it is not required [16][17]. That last condition carries the effort. Somebody has to establish which multifunction printer, scanner or old line-of-business application still relies on the pathway, because closing it without that list drops mail the business notices faster than the security team does.

The lures were ordinary: fake document requests, internal voicemail alerts, invoices and payment approvals, and fake OneDrive file shares [9]. Nothing in that set requires novelty, because the sender line does the work. A message that arrives addressed as HR or accounting, inside the recipient's working hours, from an internal-looking address, is asking to be opened [4].

What to watch

  • Whether KnowBe4 ties the 29,785 messages to a named operator or to shared sending infrastructure.
  • Whether the Monday-to-Tuesday, 2pm EST sending pattern holds into September once defenders start hunting the AuthAs: Anonymous header.
  • Whether Microsoft ships a tenant-level control that rejects unauthenticated Direct Send by default.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories