Attackers are targeting senior leaders at organizations with phishing emails using an “empty envelope” technique that bypasses Microsoft 365’s RejectDirectSend protection for Exchange Online, ReliaQuest reported Thursday.RejectDirectSend is intended to prevent abuse of the Direct Send feature, which allows unauthenticated emails to be sent from internal organizational domains. Direct Send is typically used to allow certain internet of things (IoT) devices and applications that cannot safely store credentials, such as printers, to deliver internal emails, but organizations may choose to reject Direct Send emails to prevent abuse.ReliaQuest found that unauthenticated emails that appear to come from an organization’s internal domain can still reach inboxes when the visible “From” header matches the internal domain but the Simple Mail Transfer Protocol (SMTP) envelope sender is left blank.While unauthenticated emails that use an SMTP envelope that matches the organization’s domain are blocked by RejectDirectSend, these “empty envelope” emails are still accepted and queued, ReliaQuest found in its tests. This is not a vulnerability in Exchange Online or Microsoft 365, ReliaQuest noted, as empty envelope emails are also legitimately sent for purposes such as non-delivery reports and blocking them completely could disrupt legitimate email activity.However, ReliaQuest reported that the empty envelope technique has been abused in several phishing campaigns over the past year, with the most-targeted group being senior leaders at organizations.Between September 2025 and August 2026, ReliaQuest found that 40% of phishing emails sent with an empty envelope and a spoofed “From” header impersonating the victim’s domain were sent to senior leaders, while 25% were sent to managers and sales employees, 20% were sent to individual contributors and 15% were sent to shared or service mailboxes. The most common phishing lures used in these attacks were document and file-sharing notifications, followed by payment requests, procurement invitations, loan and investment offers and meeting invitations, ReliaQuest said. Several of the emails also used SVG file attachments disguised as voicemail recordings.Bypassing RejectDirectSend does not necessarily mean an email will land in the victim’s inbox, the researchers noted. Spam filters and other email protections could cause emails that pass initial checks to be sent to a user’s junk folder. Additionally, ReliaQuest found that using a secure email gateway with IP-restricted inbound connectors blocked all tested attempts to send unauthenticated emails with a blank SMTP envelope sender.ReliaQuest recommended organizations use IP-restricted inbound connectors to only allow internal emails from approved devices and applications, remove any unnecessary mail-filtering exceptions to ensure emails that may bypass RejectDirectSend will still be filtered out of inboxes and monitor for empty envelope attacks on their organization by alerting on emails with both empty envelope senders and internal “From” addresses.The researchers concluded that empty envelope attacks are likely to continue over the next six to 12 months due to the simplicity of the attack, which requires no credentials, compromised domains or dedicated infrastructure to conduct.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds