Direct Send: How Attackers Weaponize Your Infrastructure Against You
KnowBe4, Thursday, September 10th, 2026
KnowBe4 Threat Lab examines abuse of Microsoft 365 Direct Send to deliver mail that appears internal.
KnowBe4's Threat Lab examines how attackers abuse Direct Send, the Microsoft 365 feature allowing devices and applications to send mail without authentication.
Because messages arrive through the organization's own connector they appear internal, bypassing the external-sender warnings and reputation checks that catch ordinary spoofing.
The feature exists for legitimate reasons such as scanners and line-of-business applications, so disabling it requires knowing what depends on it. The post covers the abuse pattern and the configuration changes that constrain it.