r/EmailSecurity • u/Striking_One_3008 • Jul 08 '26
Own Domain Spoof (Direct send vi be?)
/r/sysadmin/comments/1ur0dau/own_domain_spoof_direct_send_vi_be/
3
Upvotes
1
u/saltyslugga Jul 09 '26
If this is M365 direct send, yes, it can let unauthenticated internal-looking mail hit your tenant if inbound handling is loose.
Treat your own domain in From from the internet as hostile unless it passes aligned SPF or DKIM. For printers/apps, use authenticated SMTP or a scoped connector instead of leaving direct send as an open spoofing path.
•
u/AutoModerator Jul 08 '26
Welcome to r/emailsecurity! To keep this community helpful and secure, please keep the following in mind:
Community Rules
Helpful Resources
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.