Back to Feed
Saturday, Sep 5, 2026, 10:00 PM

Microsoft 365 Direct Send Bypass: How SREs Can Secure DNS and Mail Flow Against Internal Spoofing

Microsoft 365 Direct Send Bypass: How SREs Can Secure DNS and Mail Flow Against Internal Spoofing

A critical vulnerability has been uncovered in Microsoft 365's "Direct Send" feature. This bypass allows external, unauthenticated attackers to send spoofed emails that appear to originate from legitimate internal users. By exploiting the Direct Send path—originally designed to allow multi-function printers, scanners, and line-of-business applications to send emails directly via an organization's MX endpoint—attackers can circumvent standard SPF, DKIM, and DMARC checks under specific configurations.

The Mechanics of the Bypass

When an email is sent via Direct Send, it lands directly in the recipient's Exchange Online protection queue. Because the email originates from an external IP but claims to be an internal sender, Exchange may fail to flag it as external if transport rules are not strictly configured. If SRE and security teams rely solely on standard SPF checks without explicit mail flow rules to tag or block unauthenticated internal-looking mail, these spoofed messages land directly in employees' inboxes, completely bypassing multi-factor authentication (MFA) and credential checks.

SRE Best Practices for Mitigation

To secure your organization's mail infrastructure against this bypass, DevOps and SRE teams should take the following proactive steps:

  1. Implement Mail Flow Rules: Configure strict Exchange Online transport rules to detect and flag or reject any inbound messages claiming to be from your internal domain that originate from external IP addresses (unless explicitly whitelisted for Direct Send devices).
  2. Enforce Strict DMARC Policies: Move your DMARC policy to reject or quarantine rather than none to ensure non-compliant emails are handled automatically.
  3. Audit DNS and MX Configurations: Ensure your MX and SPF records do not overly expose your tenant to external relays.

How Rabbit SaaS Helps Keep Your Infrastructure Secure

As SREs, monitoring the state of your external dependencies and public-facing DNS infrastructure is paramount. Rabbit SaaS offers a suite of tools designed to help you catch and mitigate these risks:

  • Domain Audit HQ: This tool provides continuous, proactive monitoring of your domain name expiration, DNS records, and WHOIS status. It alerts your team immediately of any drifts or unexpected changes in your MX, SPF, DKIM, or DMARC records, ensuring your mail security protocols remain intact.
  • CloudStatusHQ: When major SaaS vendors like Microsoft 365 face zero-days, active exploits, or service degradations, your DevOps team needs immediate visibility. CloudStatusHQ aggregates health status feeds from third-party vendors, keeping your team updated on dependency health without manual checking.
  • Status Navigator: If your organization does experience an incident or needs to roll out mandatory mail flow maintenance, Status Navigator lets you easily communicate transparently with your internal and external stakeholders via custom-branded incident status pages.
Rabbit SaaS - Intelligent SaaS solutions