Executive Summary
A sophisticated phishing tactic is gaining traction: attackers are delivering internal-looking emails directly to Microsoft 365 mailboxes, completely bypassing Secure Email Gateways (SEGs) like Proofpoint or Mimecast.
By ignoring MX records and connecting directly to Microsoft's Exchange Online Protection (EOP), attackers exploit specific configurations to slip past defenses. The result is dangerous: messages that appear to come from colleagues, often using a null Return-Path, fail standard authentication checks (SPF/DKIM/DMARC) yet still land successfully in user mailboxes or Junk folders, invisible to your primary security layers.
Secto closes this critical gap. We provide targeted detections for direct-send anomalies, guided remediation, and business-ready reporting to eliminate this blind spot and drastically reduce response time.
Visualizing the Threat: The MX Bypass
The core of this attack is avoiding the "front door" of your email infrastructure. As illustrated below, attackers completely sidestep your SEG and connect directly to Microsoft's infrastructure.
How the Attack Works (Step-by-Step)
This attack relies on exploiting the difference between how email servers handle connections versus how email clients display information to users.
1. MX Bypass to EOP
Your organization's MX records tell the world to send mail to your SEG. Attackers ignore this. Instead, they look up your Microsoft 365 tenant's unique hostname and connect directly to Microsoft's infrastructure:
<tenant>.mail.protection.outlook.com
Because your tenant must accept mail from Microsoft infrastructure, this direct connection is often permitted by default.
2. The Null Envelope (Dodging "Reject Direct Send")
Many M365 tenants are configured to block unauthenticated mail if the "Envelope Sender" (P1) matches one of your accepted domains. Attackers know this and bypass the rule by using a null envelope:
Return-Path: <>
By using an empty return path, the message does not match your domain at the envelope level, side-stepping standard "Reject Direct Send" configurations.
3. The Internal-Looking "From" Header (P2)
While the envelope is empty, the attacker crafts the visible email header to look legitimate. Mail clients (like Outlook) display the RFC5322 From (P2) header to the user, not the envelope.
The attacker spoofs an internal address (e.g., IT support or an executive) in the P2 header to maximize click-through rates. Even though SPF, DKIM, and DMARC will fail for this spoofed address, Microsoft 365 may still deliver the message to the Junk folder, or even the Inbox, depending on user settings, because the connection itself is trusted.
Why Direct-Send Attacks Are Dangerous
This tactic is particularly effective because it breaks the traditional layered security model.
- Complete Gateway Invisibility: Because the message never traverses the SEG, there are no logs, no quarantine entries, and no centralized telemetry for security analysts to review. You cannot stop what you cannot see.
- High-Impact User Exploitation: By successfully mimicking internal senders, these attacks are highly effective tools for Credential Theft and Business Email Compromise (BEC).
- Broken Signal Alignment: Even when standard authentication protocols fail, legacy mailbox rules or configurations often allow these messages to bypass rejection, landing them where users can interact with them.
How Secto Helps Eliminate the Blind Spot
Secto is designed to catch threats that bypass perimeter defenses by integrating directly with the Microsoft 365 environment. Our platform detects these anomalies and provides a clear path to remediation.
1. Targeted Detection of "Looks Internal" Phish
Secto doesn't rely solely on gateway signals. We analyze the behavioral patterns behind Direct-Send-style messages, identifying anomalies where P1/P2 headers are mismatched in high-risk ways, providing clear evidence to responders.
2. Centralized Visibility
We end the blind spot by correlating Microsoft 365 mailbox activity with your broader email security posture, giving you a single view of threats regardless of their entry path.
3. Accelerated Response (Lower MTTR)
Secto cuts through the noise. Alerts are delivered with the necessary context: who was targeted, the attack technique used, and recommended next steps, allowing analysts to determine impact fast.
4. Executive-Ready Reporting
Quantify your risk reduction for leadership. Secto allows you to track attack volume, identify top targeted users, and demonstrate successful outcomes against threats that would have otherwise gone undetected.