We have set RejectDirectSend to true but it is still possible to send mail anonymously through tenant

Anonymous
2025-10-10T15:44:10.31+00:00

Hello

Please i need your help on this issue.

We have set RejectDirectSend to true, but it is still possible to send mail anonymously through tenant

Last Friday 3 oct 2025 we configured the tenant not to allow DirectSend from anonymous sources by setting the RejectDirectSend value to true using Powershell command.

 

When we check the status with the Get-command it looks like it is set but it is not working - it is still possible to spoof emails by sending through the mx record as anonymous.

User's image

User's image

Exchange Online
Exchange Online

A cloud-based service included in Microsoft 365, delivering scalable messaging and collaboration features with simplified management and automatic updates.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Andy David - MVP 160.3K Reputation points MVP Volunteer Moderator
    2025-10-10T17:22:37.09+00:00

    Disabling Direct Send doesnt disable the ability to spoof. It disables the ability to spoof without going through a connector or any authentication. Check with message tracking if those messages are going though an allowed connector.

    Regardless, you should always be enforcing DMARC, SPF and DKIM for your recipient domains.

    https://techcommunity.microsoft.com/blog/exchange/direct-send-vs-sending-directly-to-an-exchange-online-tenant/4439865/replies/4439933

    Direct Send, as defined in the blog post linked above in detail, is the term used for sending emails directly to your mailboxes from a domain you own without any user or on-premises connector authentication

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.