[{"data":1,"prerenderedAt":571},["ShallowReactive",2],{"blog-posts":3},[4,218,390],{"id":5,"title":6,"author":7,"body":9,"cta":202,"date":203,"description":204,"eventid":202,"extension":205,"hideInRecent":206,"layout":202,"meta":207,"moment":202,"navigation":208,"outro":209,"path":212,"seo":213,"stem":216,"tags":202,"webcast":206,"__hash__":217},"content_en/blog/exchange-online-blocks-outdated-exchange-servers.md","Your Last Exchange Server Just Got a Deadline",[8],"Sendman Team",{"type":10,"value":11,"toc":194},"minimal",[12,16,19,23,28,31,34,37,56,73,76,80,83,86,90,93,96,100,124,127,131,190],[13,14,15],"p",{},"Microsoft doesn't usually tell anyone when Exchange Online raises the minimum version it accepts mail from. The bar has been creeping up quietly with every security update since 2023. On September 2 the Exchange team made an exception and wrote a blog post about it, and the reason they did is the interesting part.",[13,17,18],{},"Since the second week of September, an Exchange 2016 or 2019 server that hands mail to Exchange Online through the hybrid inbound connector has to be on the October 2025 security update. That happens to be the last update Microsoft ever released publicly for those two versions. Anything older is now out of date as far as Exchange Online is concerned, which means a report at first, delayed mail a month later, and after three months no mail at all. Microsoft's own comment on the deadline: \"This update level was released almost a year ago, and all organizations should have updated to it.\" Fair enough.",[20,21],"at-a-glance",{":items":22},"[{\"label\":\"Affected\",\"value\":\"Exchange Server 2016 and 2019 sending to Exchange Online through an inbound connector of type OnPremises, the one a hybrid setup uses\"},{\"label\":\"Minimum build\",\"value\":\"The October 2025 security update for Exchange 2019 CU14 or CU15, or for Exchange 2016 CU23\"},{\"label\":\"In force since\",\"value\":\"The second week of September 2026\"},{\"label\":\"Full block\",\"value\":\"90 days after a server is first flagged, unless it's updated or enforcement is paused\"}]",[24,25,27],"h2",{"id":26},"what-happens-day-by-day","What Happens, Day by Day",[13,29,30],{},"Nobody gets cut off overnight. Exchange Online uses the same transport-based enforcement system Microsoft built in 2023, and it turns the screw slowly. For the first 30 days after a server is flagged, nothing changes for anyone. The server just shows up in a report that most admins have never opened. After that it gets uncomfortable in ten-day steps: Exchange Online starts answering with a temporary 450 for five minutes every hour, then ten, then twenty. Your server queues the mail and tries again, so everything still arrives, just late, and the first ticket says something like \"the scan took twenty minutes to show up\".",[13,32,33],{},"From day 61 a permanent 550 joins in. Now the message doesn't wait in a queue, it bounces. And this is the part that bites in a relay setup: the bounce goes back to the sender, and the sender is a scanner in the copy room with a from-address nobody reads. The document is simply gone. From day 91, all of them are.",[35,36],"enforcement-ladder",{},[13,38,39,40,44,45,44,48,51,52,55],{},"You can see which servers are affected in the Exchange admin center, under ",[41,42,43],"strong",{},"Reports"," > ",[41,46,47],{},"Mail flow",[41,49,50],{},"Out-of-date connecting on-premises Exchange servers",". The same page has an ",[41,53,54],{},"Enforcement Pause"," link, and PowerShell does the same thing:",[57,58,63],"pre",{"className":59,"code":60,"language":61,"meta":62,"style":62},"language-powershell shiki shiki-themes github-light github-dark","New-TenantExemptionInfo -BlockingScenario UnpatchedOnPremServer -NumberOfDays 30\n","powershell","",[64,65,66],"code",{"__ignoreMap":62},[67,68,71],"span",{"class":69,"line":70},"line",1,[67,72,60],{},[13,74,75],{},"Every tenant gets 90 pause days per calendar year, and you can split them however you like. Two things to know before you spend them. The days count from the moment you request them, so patching the next morning doesn't give them back. And a pause only ever buys time; it changes nothing about where this is heading.",[24,77,79],{"id":78},"patching-buys-months-not-years","Patching Buys Months, Not Years",[13,81,82],{},"Installing the October 2025 update takes you off the list, for now. But Microsoft was unusually open about what comes next. In several months, by their own estimate, the minimum version goes up again, and this time to a build that no public update reaches. From that day on only two kinds of servers can still hand mail to Exchange Online: the ones in the paid Extended Security Update program, whose second period ends in October 2026 with no third one planned, and Exchange Server Subscription Edition. If you're on Exchange 2019 CU14 or CU15, you can upgrade to SE in place. Exchange 2016 means a new server and a migration.",[13,84,85],{},"So the box that has hummed along in the server room for years without anyone touching it now needs a subscription, a migration project, or a plan to be switched off. There isn't a fourth option anymore, and that, more than the throttling itself, is the news in Microsoft's post.",[24,87,89],{"id":88},"about-that-one-server","About That One Server",[13,91,92],{},"We see the same picture at most hybrid customers. The mailboxes moved to Exchange Online years ago, and one Exchange server stayed behind with two jobs: it manages recipient attributes in Active Directory, and it relays mail for the printers, the scanners, the monitoring, the ERP, and whatever else in the building still speaks plain SMTP.",[13,94,95],{},"The first job hasn't needed a server since 2022. Since Exchange 2019 CU12, the Exchange Management Tools take care of recipient management on their own, and Microsoft's advice is to shut the last server down rather than uninstall it. Which leaves the relay. That's the one job keeping the server alive, and it's also, a little ironically, exactly the traffic this enforcement looks at, because everything the devices hand to that server leaves through the OnPremises connector Exchange Online is now checking.",[24,97,99],{"id":98},"what-to-do-this-week","What to Do This Week",[101,102,103,107,118,121],"ol",{},[104,105,106],"li",{},"Open the report and write down every server on it. If it's empty, that's either good news or a Partner-type connector; the enforcement only looks at the OnPremises kind, for now.",[104,108,109,110,117],{},"Compare the builds with ",[111,112,116],"a",{"href":113,"rel":114},"https://learn.microsoft.com/en-us/exchange/new-features/build-numbers-and-release-dates",[115],"nofollow","Microsoft's list of build numbers"," and install the October 2025 update wherever it's missing. For one server that's an evening, not a project.",[104,119,120],{},"Keep the pause days for a real emergency. Ninety sounds like plenty until you've used sixty of them in the wrong month.",[104,122,123],{},"Decide what happens after the next bump: ESU until October, Exchange SE, or the off switch.",[13,125,126],{},"If the relay is the only reason that server still exists, the fourth decision is the easy one. We built Sendman for exactly that case, but that's a different post.",[24,128,130],{"id":129},"sources","Sources",[132,133,134,143,151,158,165,173,181],"ul",{},[104,135,136,137,142],{},"Microsoft Exchange Team: ",[111,138,141],{"href":139,"rel":140},"https://techcommunity.microsoft.com/blog/exchange/exchange-20162019-throttling-and-blocking-up-to-the-final-public-update-baseline/4552717",[115],"Exchange 2016/2019: Throttling and Blocking up to the Final Public Update Baseline",", September 2, 2026",[104,144,136,145,150],{},[111,146,149],{"href":147,"rel":148},"https://techcommunity.microsoft.com/blog/exchange/throttling-and-blocking-email-from-persistently-vulnerable-exchange-servers-to-e/3815328",[115],"Throttling and Blocking Email from Persistently Vulnerable Exchange Servers to Exchange Online",", May 2023",[104,152,136,153],{},[111,154,157],{"href":155,"rel":156},"https://techcommunity.microsoft.com/blog/exchange/how-to-pause-throttling-and-blocking-of-out-of-date-on-premises-exchange-servers/4007169",[115],"How to pause throttling and blocking of out-of-date on-premises Exchange Servers",[104,159,136,160],{},[111,161,164],{"href":162,"rel":163},"https://techcommunity.microsoft.com/blog/exchange/announcing-period-2-exchange-20162019-extended-security-update-esu-program/4511603",[115],"Announcing Period 2 Exchange 2016/2019 Extended Security Update (ESU) program",[104,166,167,168],{},"Microsoft Learn: ",[111,169,172],{"href":170,"rel":171},"https://learn.microsoft.com/en-us/exchange/manage-hybrid-exchange-recipients-with-management-tools",[115],"Manage recipients in Exchange Hybrid environments using Management tools",[104,174,175,176],{},"heise online: ",[111,177,180],{"href":178,"rel":179},"https://www.heise.de/news/Alte-Exchange-Server-riskieren-Mailblockaden-11443696.html",[115],"Alte Exchange-Server riskieren Mailblockaden",[104,182,183,184,189],{},"CodeTwo: ",[111,185,188],{"href":186,"rel":187},"https://www.codetwo.com/admins-blog/persistently-vulnerable-exchange-server/",[115],"Exchange Online transport enforcement system explained",", the minutes per stage in the figure",[191,192,193],"style",{},"html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}",{"title":62,"searchDepth":195,"depth":195,"links":196},2,[197,198,199,200,201],{"id":26,"depth":195,"text":27},{"id":78,"depth":195,"text":79},{"id":88,"depth":195,"text":89},{"id":98,"depth":195,"text":99},{"id":129,"depth":195,"text":130},null,"2026-09-12T09:30:00+02:00","Exchange Online has started slowing down, and will eventually refuse, mail from Exchange 2016 and 2019 servers that missed the October 2025 update. If the last Exchange you own is the box that still relays the scanners, this one's for you.","md",false,{},true,{"headline":210,"copy":211},"Keep the Relay, Lose the Server","Sendman is the SMTP relay for Microsoft 365, built for exactly the server this post is about. Your printers, scanners and apps keep the logins they have, validated against Microsoft Entra ID – no app registration, no consent, nothing to change in your tenant – and their mail goes into Exchange Online without SMTP AUTH, unaffected by Microsoft's Basic Authentication retirement.","/blog/exchange-online-blocks-outdated-exchange-servers",{"title":214,"description":215},"Exchange Online Now Throttles Exchange 2016 and 2019","Since September 2026, Exchange Online throttles and then blocks mail from Exchange 2016 and 2019 servers below the October 2025 update. What to do now.","blog/exchange-online-blocks-outdated-exchange-servers","0SixmPkk4zfl24xMmpZYIIe0T7AC_RYgyuOnFSIGKvQ",{"id":219,"title":220,"author":221,"body":222,"cta":202,"date":378,"description":379,"eventid":202,"extension":205,"hideInRecent":206,"layout":202,"meta":380,"moment":202,"navigation":208,"outro":381,"path":384,"seo":385,"stem":388,"tags":202,"webcast":206,"__hash__":389},"content_en/blog/smtp-auth-basic-authentication-retirement-timeline.md","Basic Auth for SMTP Didn't End in April",[8],{"type":10,"value":223,"toc":371},[224,227,230,233,237,240,243,247,262,266,273,276,279,282,289,293,296,299,301],[13,225,226],{},"If you've read that Microsoft switched off Basic Authentication for SMTP AUTH on April 30, you're in good company. Plenty of printer dealers and IT service providers still say so on their websites, and for a few months it was even true, in the sense that it was the plan. In January Microsoft threw that plan out. The date that replaced it is later and a good deal softer, which is good news right up to the point where someone reads it as permission to stop working on it.",[13,228,229],{},"The back and forth explains a lot, so here's the short version. When Microsoft turned off Basic Auth for POP, IMAP, EWS and the rest of Exchange Online in October 2022, SMTP AUTH was the one protocol it left alone, with the memorable line \"We are not touching SMTP AUTH and are done turning it off for now.\" In April 2024 it set a date anyway, September 2025, which later became a gradual rejection starting on March 1, 2026 and reaching every submission on April 30. On January 27 came the post that replaced all of it, and Microsoft's reasoning is worth quoting: \"many customers continue to face real challenges modernizing legacy email workflows\". Anyone who has asked a copier vendor about OAuth knows exactly what that sentence means.",[20,231],{":items":232},"[{\"label\":\"Until December\",\"value\":\"Nothing changes, Basic Auth for SMTP AUTH works as it does today\"},{\"label\":\"End of December 2026\",\"value\":\"Disabled by default for existing tenants, and admins can turn it back on\"},{\"label\":\"New tenants\",\"value\":\"Tenants created after December 2026 don't get it at all; OAuth is the supported method\"},{\"label\":\"Second half of 2027\",\"value\":\"Microsoft announces the date it goes away for good\"}]",[24,234,236],{"id":235},"what-disabled-by-default-means-for-you","What \"Disabled by Default\" Means for You",[13,238,239],{},"For existing tenants there's still a way back. At the end of December Microsoft turns Basic Auth for SMTP AUTH off, and an admin can turn it on again. The announcement doesn't say which switch that will be, so the honest expectation is this: one morning around New Year the scanners stop sending, and someone who knows where to look fixes it in a few minutes. That sounds harmless until you picture the last week of December, with half the IT team on holiday and accounting trying to get the year-end statements out of the ERP.",[13,241,242],{},"And turning it back on only buys time until Microsoft names the final date, which it plans to do in the second half of 2027. After that there's nothing left to switch. Tenants created after December never get Basic Auth for SMTP in the first place, which matters more than it sounds if a tenant migration or a carve-out is on next year's list: the new tenant will refuse logins the old one accepted without complaint.",[24,244,246],{"id":245},"find-out-who-still-uses-it","Find Out Who Still Uses It",[13,248,249,250,44,252,44,254,257,258,261],{},"You probably have a rough idea, and it's probably incomplete. The Exchange admin center has a report for exactly this, under ",[41,251,43],{},[41,253,47],{},[41,255,256],{},"SMTP AUTH clients",". It lists every sender address that submits mail over SMTP AUTH, shows whether it signs in with Basic Auth or OAuth and which TLS version it speaks, and goes back up to 90 days. The sign-in logs in Microsoft Entra ID, filtered to the client app ",[41,259,260],{},"Authenticated SMTP",", tell the same story from the identity side, including the IP addresses the logins come from. Between the two you'll usually find the copier on the third floor, a monitoring server that predates everyone on the team, and one application nobody admits to owning.",[24,263,265],{"id":264},"where-each-device-can-go","Where Each Device Can Go",[13,267,268,269,272],{},"Scripts and your own applications are the easy part. Microsoft Graph and cmdlets like ",[64,270,271],{},"Send-MgUserMail"," send mail with modern authentication, and rewriting a script is an afternoon's work.",[13,274,275],{},"Devices whose vendor has shipped OAuth support need a firmware update and a bit of Entra configuration, and then they're done. Everything else is where it gets slow. Tony Redmond put it politely: \"I hear of many blank looks when customers ask vendors about their plans to upgrade devices to support OAuth for client submissions.\"",[13,277,278],{},"If a device only ever mails people inside the company, High Volume Email is worth a look. It has been generally available since the end of March, costs $42 per million recipients and, somewhat against the direction of everything else in this post, keeps accepting Basic Auth on its own endpoint until September 2028. The limits are real, though: internal recipients only, at most 50 recipients and 10 MB per message, and nothing ever reaches a supplier or a customer.",[13,280,281],{},"For mail that has to leave the company, Microsoft points to Azure Communication Services. It speaks SMTP, but the password is the client secret of an Entra app registration, and client secrets expire. Somebody will have to change the scanner's password on a schedule, which is exactly the kind of task that gets remembered the day after it was due.",[13,283,284,285,288],{},"And then there are the devices that can't do any of that, which in most buildings is more of them than anyone would like. They need a relay that accepts the login they already have. An on-premises Exchange server does that job, as long as Exchange Online still takes its mail, and that has turned into ",[111,286,287],{"href":212},"a story of its own this month",".",[24,290,292],{"id":291},"dont-wait-for-the-switch","Don't Wait for the Switch",[13,294,295],{},"The new timeline gives you more than a year until the final date, but it doesn't give you a quiet December. If you open the report this month, you can move the easy cases in October, sort out the difficult ones in November, and spend the last week of the year the way it was meant to be spent.",[13,297,298],{},"We built Sendman for that last group, the devices that will never learn OAuth.",[24,300,130],{"id":129},[132,302,303,311,319,326,333,340,348,355,362],{},[104,304,136,305,310],{},[111,306,309],{"href":307,"rel":308},"https://techcommunity.microsoft.com/blog/exchange/updated-exchange-online-smtp-auth-basic-authentication-deprecation-timeline/4489835",[115],"Updated Exchange Online SMTP AUTH Basic Authentication Deprecation Timeline",", January 27, 2026",[104,312,136,313,318],{},[111,314,317],{"href":315,"rel":316},"https://techcommunity.microsoft.com/blog/exchange/exchange-online-to-retire-basic-auth-for-client-submission-smtp-auth/4114750",[115],"Exchange Online to retire Basic auth for Client Submission (SMTP AUTH)",", April 15, 2024, with later updates",[104,320,167,321],{},[111,322,325],{"href":323,"rel":324},"https://learn.microsoft.com/en-us/exchange/monitoring/mail-flow-reports/mfr-smtp-auth-clients-report",[115],"SMTP AUTH clients report in the new EAC in Exchange Online",[104,327,167,328],{},[111,329,332],{"href":330,"rel":331},"https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/authenticated-client-smtp-submission",[115],"Enable or disable SMTP AUTH in Exchange Online",[104,334,167,335],{},[111,336,339],{"href":337,"rel":338},"https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/how-to-set-up-a-multifunction-device-or-application-to-send-email-using-microsoft-365-or-office-365",[115],"How to set up a multifunction device or application to send email using Microsoft 365",[104,341,136,342,347],{},[111,343,346],{"href":344,"rel":345},"https://techcommunity.microsoft.com/blog/exchange/high-volume-email-continued-support-for-basic-authentication--other-important-up/4411197",[115],"High Volume Email: Continued support for Basic Authentication & other important updates",", May 6, 2025",[104,349,167,350],{},[111,351,354],{"href":352,"rel":353},"https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/high-volume-mails-m365",[115],"Manage High Volume Email for Microsoft 365",[104,356,167,357],{},[111,358,361],{"href":359,"rel":360},"https://learn.microsoft.com/en-us/azure/communication-services/quickstarts/email/send-email-smtp/smtp-authentication",[115],"Set up SMTP authentication for sending emails with Azure Communication Services",[104,363,364,365,370],{},"Office 365 for IT Pros: ",[111,366,369],{"href":367,"rel":368},"https://office365itpros.com/2026/01/29/smtp-auth-basic-retirement/",[115],"SMTP AUTH Client Submission Retirement Delayed",", January 29, 2026",{"title":62,"searchDepth":195,"depth":195,"links":372},[373,374,375,376,377],{"id":235,"depth":195,"text":236},{"id":245,"depth":195,"text":246},{"id":264,"depth":195,"text":265},{"id":291,"depth":195,"text":292},{"id":129,"depth":195,"text":130},"2026-09-12T09:20:00+02:00","If you've read that Microsoft switched off Basic Authentication for SMTP AUTH this spring, you read a plan Microsoft scrapped in January. The real date is the end of December, and it's a softer one than the old, for now.",{},{"headline":382,"copy":383},"Keep the Logins, Lose the Deadline","Sendman is the SMTP relay for Microsoft 365, built for the devices that will never learn OAuth. They keep the logins they have, validated against Microsoft Entra ID – no app registration, no consent, nothing to change in your tenant – and their mail goes into Exchange Online without SMTP AUTH, unaffected by Microsoft's Basic Authentication retirement.","/blog/smtp-auth-basic-authentication-retirement-timeline",{"title":386,"description":387},"SMTP AUTH Basic Auth Retirement: The Real Timeline","Microsoft scrapped the April 2026 cut-off. SMTP AUTH Basic Authentication is disabled by default at the end of December 2026. What changes, and what to do.","blog/smtp-auth-basic-authentication-retirement-timeline","YhasNFKlRj3K_zEFjApVp-xS0Iaiq5nF55Qs6dXVkaM",{"id":391,"title":392,"author":393,"body":394,"cta":202,"date":559,"description":560,"eventid":202,"extension":205,"hideInRecent":206,"layout":202,"meta":561,"moment":202,"navigation":208,"outro":562,"path":565,"seo":566,"stem":569,"tags":202,"webcast":206,"__hash__":570},"content_en/blog/reject-direct-send-without-breaking-scanners.md","Closing Direct Send Without Silencing the Scanners",[8],{"type":10,"value":395,"toc":552},[396,399,402,405,409,412,421,424,432,435,439,442,469,476,479,483,486,493,495,509,516,518,550],[13,397,398],{},"Direct Send was never meant to be clever. It exists so that a scanner or a small application can drop mail straight onto your tenant's MX endpoint, with one of your own addresses as the sender, without signing in anywhere. Microsoft describes it as something that \"mimics incoming anonymous emails from the internet, apart from the sender domain\", which is a polite way of saying that the only thing telling your scanner apart from anyone else on the internet is the address it claims to have.",[13,400,401],{},"In May 2025 someone put that to use. Varonis traced a campaign that reached more than 70 organizations, most of them in the US, with mail that looked internal because, as far as Exchange Online could tell, it was. One line of PowerShell against the tenant's smart host, the victim's own address as the sender, and a PDF with a QR code leading to a fake Microsoft sign-in page. The lures were missed-call and fax notifications, the kind of mail a multifunction device sends every day, which is precisely why nobody thought twice.",[20,403],{":items":404},"[{\"label\":\"What it is\",\"value\":\"Mail sent anonymously to your tenant's MX endpoint with one of your accepted domains as the sender\"},{\"label\":\"The switch\",\"value\":\"RejectDirectSend in the organization config, introduced in April 2025 and off by default\"},{\"label\":\"What still gets in\",\"value\":\"Mail that arrives over an inbound connector you set up, matched by IP address or certificate\"},{\"label\":\"New tenants\",\"value\":\"Microsoft plans to switch it on by default, with no way to turn it off\"}]",[24,406,408],{"id":407},"the-switch-microsoft-added","The Switch Microsoft Added",[13,410,411],{},"Since April 2025 there's a real off switch, and it's one line:",[57,413,415],{"className":59,"code":414,"language":61,"meta":62,"style":62},"Set-OrganizationConfig -RejectDirectSend $true\n",[64,416,417],{"__ignoreMap":62},[67,418,419],{"class":69,"line":70},[67,420,414],{},[13,422,423],{},"It takes effect within about half an hour. From then on, anonymous mail that uses one of your domains in the envelope sender gets turned away at the door, unless it comes in over an inbound connector you've configured, and whoever sent it sees this:",[57,425,430],{"className":426,"code":428,"language":429,"meta":62},[427],"language-text","550 5.7.68 TenantInboundAttribution; Direct Send not allowed for this organization from unauthorized sources\n","text",[64,431,428],{"__ignoreMap":62},[13,433,434],{},"Microsoft has also said it wants this on by default for new tenants, and that those tenants won't be able to turn it off. The direction is clear, even if the date isn't.",[24,436,438],{"id":437},"find-out-who-is-using-it-first","Find Out Who Is Using It First",[13,440,441],{},"Most tenants haven't flipped the switch yet for one simple reason: nobody knows what else goes quiet when they do. Microsoft suggests starting with your SPF record, because whatever sends through Direct Send without being listed there already has trouble getting delivered. For the actual traffic, the Change Optics report, which Microsoft released as a preview in the Exchange admin center, shows example messages the setting would reject. A historical message trace for everything received without a connector goes back up to 90 days:",[57,443,445],{"className":59,"code":444,"language":61,"meta":62,"style":62},"Start-HistoricalSearch -ReportTitle \"Direct Send\" -ReportType ConnectorReport `\n  -ConnectorType NoConnector -Direction Received `\n  -StartDate (Get-Date).AddDays(-89) -EndDate (Get-Date) `\n  -NotifyAddress admin@contoso.com\n",[64,446,447,452,457,463],{"__ignoreMap":62},[67,448,449],{"class":69,"line":70},[67,450,451],{},"Start-HistoricalSearch -ReportTitle \"Direct Send\" -ReportType ConnectorReport `\n",[67,453,454],{"class":69,"line":195},[67,455,456],{},"  -ConnectorType NoConnector -Direction Received `\n",[67,458,460],{"class":69,"line":459},3,[67,461,462],{},"  -StartDate (Get-Date).AddDays(-89) -EndDate (Get-Date) `\n",[67,464,466],{"class":69,"line":465},4,[67,467,468],{},"  -NotifyAddress admin@contoso.com\n",[13,470,471,472,475],{},"If you have Defender for Office 365 Plan 2, Advanced Hunting finds the same mail in ",[64,473,474],{},"EmailEvents"," where the connector field is empty. One thing to know before you read the results: these reports work best when your MX points to a gateway that comes in over its own connector. If your MX points straight at Exchange Online, all your ordinary inbound mail arrives without a connector as well, and you'll want to filter for your own domains as the sender.",[13,477,478],{},"What turns up is rarely a surprise, just a longer list than expected: the copiers, a building management system, a label printer in the warehouse, and every now and then a cloud service that sends invoices in your name. If you'd like to see the effect before you commit, Microsoft's own middle ground is a mail flow rule that quarantines this kind of mail instead of rejecting it. You lose nothing, and a week later you know exactly what the switch would have stopped.",[24,480,482],{"id":481},"moving-the-scanners-out-of-the-way","Moving the Scanners Out of the Way",[13,484,485],{},"Microsoft's answer for legitimate senders is an inbound connector of type Partner that trusts your office's public IP address, or a certificate, which few scanners have in practice. It costs nothing, and for a single site with a static address it works. The small print: the address must not be shared with anyone outside your organization, every site with its own internet breakout needs its own entry, and the IP address becomes the only key. Anything behind it can send as anyone in your domain, including the laptop in accounting that clicked on the wrong fax notification.",[13,487,488,489,492],{},"Devices that can sign in and only ever mail colleagues can move to High Volume Email, which we looked at in the ",[111,490,491],{"href":384},"post on SMTP AUTH",". The rest were on Direct Send in the first place because they can't do TLS or a login, and they need a relay that accepts what they can do and still decides who may send as whom.",[24,494,99],{"id":98},[101,496,497,500,503,506],{},[104,498,499],{},"Run the no-connector message trace, open the Change Optics report, and write down every source you find.",[104,501,502],{},"Give the legitimate ones a proper path: a partner connector for known IP addresses, High Volume Email for devices that only mail internally, a relay for the rest.",[104,504,505],{},"Put a quarantine rule in place for a week and look at what lands there.",[104,507,508],{},"Then set RejectDirectSend and keep an eye on 5.7.68 bounces for a few days.",[13,510,511,512,515],{},"We built Sendman as that relay. The scanner signs in, or sends from an address range you allow, and it may send as ",[64,513,514],{},"scan@contoso.com"," but not as your CEO.",[24,517,130],{"id":129},[132,519,520,528,536,541],{},[104,521,136,522,527],{},[111,523,526],{"href":524,"rel":525},"https://techcommunity.microsoft.com/blog/exchange/introducing-more-control-over-direct-send-in-exchange-online/4408790",[115],"Introducing more control over Direct Send in Exchange Online",", April 28, 2025, updated since",[104,529,136,530,535],{},[111,531,534],{"href":532,"rel":533},"https://techcommunity.microsoft.com/blog/exchange/direct-send-vs-sending-directly-to-an-exchange-online-tenant/4439865",[115],"Direct Send vs sending directly to an Exchange Online tenant",", August 4, 2025",[104,537,167,538],{},[111,539,339],{"href":337,"rel":540},[115],[104,542,543,544,549],{},"Varonis Threat Labs: ",[111,545,548],{"href":546,"rel":547},"https://www.varonis.com/blog/direct-send-exploit",[115],"Ongoing Campaign Abuses Microsoft 365's Direct Send to Deliver Phishing Emails",", June 26, 2025",[191,551,193],{},{"title":62,"searchDepth":195,"depth":195,"links":553},[554,555,556,557,558],{"id":407,"depth":195,"text":408},{"id":437,"depth":195,"text":438},{"id":481,"depth":195,"text":482},{"id":98,"depth":195,"text":99},{"id":129,"depth":195,"text":130},"2026-09-12T09:10:00+02:00","Direct Send lets anyone on the internet drop mail into your tenant as one of your own users, and last year attackers noticed. Exchange Online can reject it now. The catch is the scanner that has quietly relied on it for years.",{},{"headline":563,"copy":564},"Keep the Scanners, Close the Side Door","Sendman is the SMTP relay for Microsoft 365. Devices sign in with the logins they have, validated against Microsoft Entra ID – no app registration, no consent, nothing to change in your tenant – or send without a login from the address ranges you allow, and your policies decide who may send as whom.","/blog/reject-direct-send-without-breaking-scanners",{"title":567,"description":568},"Reject Direct Send Without Breaking Your Scanners","Attackers use Direct Send to spoof your own users. Exchange Online can reject it, but scanners often depend on it. How to find them and move them first.","blog/reject-direct-send-without-breaking-scanners","wiY0T292f-BwTeHBDdyp9r0iYoDcsE7hl_gmQmYbQ24",1789226271571]