Phishing Emails Use New Technique to Bypass Microsoft 365 Security Filters

KnowBe4 Team | Sep 15, 2026

Threat actors are using phishing emails with blank SMTP sender fields to bypass Microsoft 365 security filters, according to researchers at ReliaQuest.

Microsoft 365 Exchange Online uses a feature called “RejectDirectSend” to block unauthenticated Direct Send emails from an organization’s trusted domain. If an attacker omits the domain field from these emails, however, RejectDirectSend will no longer block the messages. Attackers can therefore exploit this technique to impersonate internal users.

“ReliaQuest identified numerous instances of this empty-envelope pattern over the past year, frequently used against executives, managers, and business-facing roles,” the researchers write. “In one case, a message failed every sender authentication check and was classified as high-confidence phishing but still reached the inbox because the spoofed executive address was listed as an allowed sender. Defenders should therefore treat filtering exceptions as high-risk trust decisions, particularly when they cover privileged or frequently impersonated users.” The attacks observed by ReliaQuest used routine phishing lures that employees would expect to see throughout their workdays.

“The delivered emails used familiar business themes rather than technically sophisticated lures,” ReliaQuest says. “Document and file-sharing notifications were the most common, followed by payment and remittance requests, procurement invitations, loan and investment offers, and a meeting invitation. These themes blend into routine workflows and give recipients a plausible reason to open a document, follow a link, or act on a financial request. Multiple cases used SVG (graphics file type) attachments presented as voicemail recordings, combining a familiar notification theme with a browser-rendered file format that security products may handle inconsistently.” The phishing emails are targeting employees who handle financial responsibilities, attempting to trick them into authorizing payments or sending sensitive information.

“ReliaQuest assesses with moderate confidence that attackers in the cases we investigated favored recipients who routinely process invoices, bids, payment instructions, and externally shared documents,” the researchers write. “Attackers likely target these users because their authority and routine responsibilities make financial and document-sharing lures more credible, and a successful compromise can enable fraudulent payments, sensitive data theft, or further access. Procurement and customer-facing mailboxes are also attractive targets because they routinely receive unfamiliar external messages that multiple users may need to act on. Permissive allow rules for these identities can further increase the risk by giving attackers a repeatable way to deliver phishing under a trusted internal address.”

ReliaQuest has the story: https://reliaquest.com/blog/threat-spotlight-one-blank-field-bypasses-direct-send-control/

 

See KnowBe4 Cloud Email Security in Action

Request a personalized demo today to see how KnowBe4's Cloud Email Security products will enhance your email security.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, email and collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.