Direct Send “Vulnerability”

Direct Send is a way for organizations to send email internally. Like messages from a webserver, a confirmation for a meeting, or whatever. This worked fine for many years in on-prem Exchange email environments. So Exchange Online came out (back in 2017 or whenever) and it has a “feature” where anyone can send an email to your organization and use Direct Send! You can spoof whoever you want the email to be from, write whatever you want, and then just send the email – and it will bypass all email security gateways! Is your company spending $500,000 per year to have Proofpoint block spam and phishing? Doesn’t matter, Direct Send bipasses it all, thanks to Exchange Online! Microsoft did actually recently implement a new “feature” that allows you to turn Direct Send off, but this is problematic for organizations that have hundreds of applications using it.

Congrats Microsoft for another great feature!