Skip to content

Ghost Sender: MX Record Enables Bypass of Exchange Online Gateways

In brief: Direct access to Exchange Online submission endpoints via MX records circumvents upstream email security gateways and authentication mechanisms.

Attackers can bypass email gateways by communicating directly with the Exchange Online submission endpoint, rendering SPF, DKIM and DMARC validation ineffective. Microsoft does not classify this phenomenon as a vulnerability, but rather as an architectural feature of the platform.

The “Ghost Sender” attack method exploits the fact that a tenant’s MX record allows direct access to the Exchange Online service. Instead of contacting upstream email gateways, attackers communicate directly with Microsoft infrastructure. In this way, they bypass the security checks that third-party solutions normally perform before message delivery.

In this approach, standard authentication mechanisms such as SPF (Sender Policy Framework), DKIM (DomainKeys Identified Mail) and DMARC (Domain-based Message Authentication, Reporting and Conformance) become ineffective, since these validations originate from the upstream gateways being circumvented. Microsoft does not regard this constellation as an exploitable vulnerability, but rather describes it as a limitation that lies in the architecture of Exchange Online.

CISOs should review their Inbound Connectors. These allow configuration of connection rules that specify which sources are permitted to deliver messages directly to Exchange Online. An audit of existing connectors may reveal overly permissive settings that allow direct delivery without upstream gateway security measures being applied.


Source: www.security-insider.de · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 of the EU AI Act. Paraphrase and classification via Lumi News Pipeline v1.7.3.

Share on: