Microsoft 365
--
Questions
--
Followers
Top Experts
Hey all got a new notification re an issue with Direct Send. Proofpoint released cybersecurity alert 2 weeks ago it seems. https://www.proofpoint.com/us/blog/email-and-cloud-threats/attackers-abuse-m365-for-internal-phishing
We use Papercut to scan to email.
System was setup using SMTP Relay.
SPF records has been added of their public ip address and a connector in 365 has been added to allow email coming from the specified public ip.
Am i covered here is basically what im asking, with what i have setup?
Zero AI Policy
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
The biggest question here is where is your MX pointed at? Customers using “complex” routing, such as those leveraging Proofpoint in front of Exchange Online, are the ones in risk of this direct send abuse. If the MX points to ExO, you are already protected.
Check out the latest blog post for additional details and guidance: https://techcommunity.microsoft.com/blog/exchange/direct-send-vs-sending-directly-to-an-exchange-online-tenant/4439865
Hey Amit
ta for the reply. i thought SMTP Auth that used some sort of Auth in it wouldnt be considered Direct Send. Has email address and password as in needed to send an email, am i worng in this?
@Vasil the mx records go through Mimecast, incoming and outgoing. I didnt think of this so i suppose i thought with what Proofpoint were saying, i thought it was still an issue. i didnt actually cop Proofpoint mentioning if you had their system it wouldnt be an issue. Now i might have jsut missed it but they might have said it. i will look at it again and what you sent.
Fact we use Mimecast ill have to check but i expect the rules put in place will already restrict direct send. we have to check
Ta for the replies. much appreciated






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
@Vasil if i turn off Direct Send in 365 is there a way i can check if 365 is receiving emails using direct send. There is no inbound connector rule setup in 365 at all. All emails sent to the company are sent through mx record pointing to Mimecast alright but this direct send bypasses the mx record that is what im getting from this all.
Would like to know if id be stopping legit emails coming in if i can run some sort of report on it to check before i just turned off direct send!
I disabled it. Using Set-OrganizationConfig -RejectDirectSend $true
Refer: https://www.varonis.com/blog/direct-send-exploit
SMTP Auth perfect, thought i was losing it there.
So MX records dont come into this then at all. So min id need some sort of connector rule in 365 to well only accept emails coming from mimecast systems.
Or turn off Direct Sned, this does seem like the easier option
Me tuning off Direct Send though, this from my understanding wouldn't cause an issue for Papercut and the SMTP relay setup?
its as youve said anyone can really just use that setting to try and relay emails/direct send through to an internal user really using as Microsoft call it the endpoint. be the default MX records i suppose for 365 if not using the likes of a mimecast for example?
Sorry just really trying to make sure i understand correctly

Get a FREE t-shirt when you ask your first question.
We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.
The blog post I linked to above shows how you can check whether your tenant receives messages via Direct send, and what methods you can use to restrict that if needed. The recommended solution would be to drop any such messages, unless they are coming from a connector configured for the third-party service (i.e. Mimecast in you case). Without such connector, you are exposed.
The article above also discusses some alternatives. Make sure to also read the comments, where many common questions are addressed.
ive seen that turning off direct send can block OOO from 365 and notifications from 365 also. you have that issue at all guys?






EARN REWARDS FOR ASKING, ANSWERING, AND MORE.
Earn free swag for participating on the platform.
Microsoft 365
--
Questions
--
Followers
Top Experts
Office 365 is a group of software plus services subscriptions that provides productivity software and related services to its subscribers. Office 365 allows the use of Microsoft Office apps on Windows and OS X, provides storage space on Microsoft's cloud storage service OneDrive, and grants 60 Skype minutes per month. Office 365 includes e-mail and social networking services through hosted versions of Exchange Server, Skype for Business Server, SharePoint and Office Online, integration with Yammer, as well as access to the Office software. All of Office 365's components can be managed and configured through an online portal; users can be added manually, imported from a CSV file, or Office 365 can be set up for single sign-on with a local Active Directory using Active Directory Federation Services.