The Microsoft 365 “Direct Send” loophole: what every business needs to know

Email Security >

The Microsoft 365 “Direct Send” loophole: what every business needs to know

By Cian Fitzpatrick | 10th October 2025

Microsoft office

Table of Contents

  1. The Microsoft 365 “Direct Send” loophole: what every business needs to know.
  2. What is Direct Send?
  3. How the attack works.
  4. Why this matters for your business.
  5. How to protect your organisation.
    • Review your Direct Send configuration.
    • Strengthen your email authentication.
    • Monitor internal-looking emails sent from outside your network.
    • Invest in cybersecurity awareness training.
    • Partner with a trusted email security provider.
  6. The bigger picture.
  7. How Topsec helps businesses stay secure.

Introduction

Cybercriminals are a clever bunch and they’re getting smarter about how they disguise phishing emails. One recent example involves a Microsoft 365 feature called Direct Send. It was designed to make life easier by letting certain devices send emails without logging in. However, this convenience is capable of being exploited.

Evidence shows that attackers are using Direct Send to send emails that look like they come from within a company. No accounts are hacked and no passwords are stolen. Instead, the attackers are taking advantage of the way Microsoft 365 lets some systems send messages without authentication.

What is Direct Send?

Direct Send is a built-in Microsoft 365 feature that lets devices like printers, scanners or internal systems send emails straight to users without needing to sign in. In a trusted environment, it’s easy to see how this feature can make everyday office tasks easier and save time.

Yet this same convenience also holds the door open to risk.

All it takes is for a cybercriminal to know your organisation’s Microsoft 365 tenant name and the email address of someone inside your company. They can then use that information to send what looks like a genuine internal email. To the recipient, it appears to come from a trusted colleague or system. However, in reality the email has been sent from outside the organisation.

How the attack works

In this particular type of phishing attack, cybercriminals send emails that look like voicemail or fax notifications. Each message contains either a PDF attachment or a QR code that leads to a fake login page. Once recipients scan the code or open the file, they are taken to a convincing Microsoft 365-style website that prompts them to enter their login credentials.

Security blockers let these messages pass because they appear to come from within the organisation. While the message headers showed clear signs of forgery, such as external IP addresses and failed authentication checks, those details are hidden from most users and can easily slip past default filters.

Keep your email ecosysytem secure

Contact Us

Why this matters for your business

This type of phishing attack shows how sophisticated cyber threats have become. 

Modern attackers no longer rely on breaching accounts. They now manipulate the systems we trust most. By exploiting legitimate Microsoft 365 features, bad actors can send believable messages that bypass basic email defences and take advantage of human trust.

When an employee sees what appears to be an internal email, the likelihood of them clicking a link or entering a password increases significantly. This highlights the need for stronger email protection and continuous cybersecurity awareness across every level of the business.

How to protect your organisation

This is a threat worth paying attention to. The good news is that there are clear and practical steps your organisation can take to stay protected.

  1. Review your Direct Send configuration.
    If your business does not rely on this feature, disable it. If you do need it, restrict access to specific devices or trusted IP addresses. Regularly review who and what can send emails this way.
  2. Strengthen your email authentication.
    Implement and enforce strong SPF, DKIM and DMARC policies. A DMARC policy set to “reject” ensures that unauthorised emails cannot reach your users, adding a powerful layer of phishing prevention.
  3. Monitor internal-looking emails sent from outside your network.
    Modern email security solutions can detect when a message claims to be from your company domain but originates from an external source. These messages should be quarantined or flagged immediately.
  4. Invest in cybersecurity awareness training.
    Attackers now use QR codes, voicemail attachments and other creative lures because they know these methods appear trustworthy. Ongoing training helps staff pause and verify before acting on suspicious messages.
  5. Partner with a trusted email security provider.
    Working with a dedicated email protection service ensures your systems are monitored for emerging threats. Providers like Topsec continuously track new phishing techniques and update defences to keep your organisation ahead of attackers.

The bigger picture

The Direct Send exploit is a reminder that strong security is about more than just technology. It is about understanding how systems behave and where vulnerabilities may appear. Cybercriminals will always look for convenience features they can twist to their advantage.

To stay secure, organisations must combine the right tools, the right policies and the right culture. Everyone plays a role, from leadership teams setting the tone for security awareness to employees practising safe email habits every day.

How Topsec helps businesses stay secure

Our team specialises in keeping businesses safe from phishing and spoofing attacks. With Topsec’s email security in place, harmful messages are stopped and filtered out long before they ever reach your inbox.

We help organisations implement robust Microsoft 365 security configurations, strengthen DMARC policies and raise staff awareness of new threats.

Cyber threats continue to evolve, but you can stay one step ahead. With Topsec as your partner, you gain continuous visibility, expert guidance and proven protection for your most important communications. Together, we make your organisation safer, stronger and more resilient in an increasingly digital world.

Contact us today for a no obligation call to discover how we can help your organisation stay safe.

Contact Topsec for all your email security needs

Contact Us