m365-direct-send

An email that appears to be from the accounting department or the company’s CEO, using your actual email address, can be sent by attackers without them having to hack into any account—using a feature in Microsoft 365.

The feature is called Direct Send, and it’s legitimate: it allows printers, scanners, and some older applications to send email through the company’s server without a dedicated account. The problem is that an attacker could use this same method to send messages that appear to come from internal addresses—HR, accounting, the administrator—without needing anyone’s password.

Because the message enters through the company’s own infrastructure, it appears as “internal” and bypasses many of the warnings displayed for emails coming from outside. Researchers at KnowBe4 counted tens of thousands of such messages in a recent campaign, with lures such as “invoice to be paid,” “internal voicemail,” or “request for proposal.”

For a small business, the risk is high precisely because an “internal” email from the director requesting an urgent payment or some information is much more credible than one that clearly comes from outside the company. That’s how “order from the boss” fraud works.

The good news is that the port can be closed, and often it isn't even used. If no printer or application depends on Direct Send, it can be disabled.

What you need to do:

  • If you use Microsoft 365, ask your administrator to enable “Reject Direct Send” in Exchange Online.
  • Set a simple rule: any email requesting payment or sensitive information must be confirmed through another channel—a phone call or a direct conversation.
  • Request a strict DMARC policy (p=reject) for your company’s domain so that messages that spoof your address are rejected.

Technology blocks the entry point, but the habit of verifying any request for money through another channel is what stops fraud—even when the message seems perfect.

This article was generated with AI assistance.

Request a quote

← All news