A newly disclosed misconfiguration in Microsoft Exchange Online dubbed Ghost-Sender allows attackers to spoof emails from any sender to any recipient within a target tenant, completely bypassing SPF, DKIM, and DMARC email authentication controls.
Researchers at InfoGuard have identified that Ghost-Sender exploits a fundamental architectural behavior in Exchange Online.
When an organization uses Exchange Online or on-premises Exchange in hybrid mode alongside an external MX record such as a third-party spam filter or email gateway, Exchange Online’s built-in filtering is effectively bypassed.
Ghost-Sender Vulnerability
An attacker can send emails directly to the tenant’s *.mail.protection.outlook.com endpoint, skipping the external filter entirely and delivering spoofed mail straight to the user’s inbox.
Spoofed emails arrive without any warning, even when the spoofed domain has properly configured SPF, DKIM, and DMARC policies.
In testing, researchers successfully delivered a spoofed email from noreply@microsoft.com a domain with robust email authentication directly to a user’s inbox.
For internal senders, Outlook even resolves the spoofed sender’s profile picture, making the attack nearly indistinguishable from a legitimate communication. The entire attack can be executed with a single PowerShell one-liner targeting the tenant’s mail protection endpoint.

The researchers’ preliminary analysis found that fewer than half of Exchange Online environments that use an external MX record have any mitigation in place.
Among scanned bug bounty domains, over 20% that use Exchange Online appear vulnerable, indicating a widespread, systematic misconfiguration rather than an isolated edge case.
More critically, Microsoft support confirmed to the researchers that this issue, or a related one, is being actively abused in the wild.
Microsoft briefly deployed an internal spoofing mitigation on April 22, 2026, then rolled it back on April 27, leaving organizations exposed once again.
As of Microsoft’s last communication on May 29, 2026, the company classified the issue as a “known architectural limitation” rather than a product vulnerability, and no platform-level fix has been issued. Ghost-Sender opens the door to high-impact phishing and fraud scenarios.
Attackers can send fake invoices that appear to originate from trusted vendors like Microsoft or financial institutions, commit CEO fraud and Business Email Compromise (BEC) attacks using spoofed internal executive addresses, or launch broad phishing campaigns impersonating any external sender all without triggering authentication warnings in the recipient’s inbox.
Infoguard stated that not all Exchange Online setups carry the same risk. Organizations whose MX record points directly to Exchange Online Protection are not vulnerable.
However, any setup using an external MX record without additional hardening is exposed by default. Standard “Your Organization” connectors, even with Enhanced Filtering enabled, do not mitigate the flaw.
Preset and custom anti-phishing policies enforcing “Honor DMARC” are also ineffective when the MX record does not point to Microsoft 365. Notably, Microsoft’s own Configuration Analyzer raises no warnings for any of these vulnerable setups.
Mitigations
Two configurations have been confirmed to block Ghost-Sender. The first is deploying a Partner Organization inbound connector with a wildcard domain match and IP or certificate-based sender restriction.
The second is creating a priority-0 mail flow rule that quarantines all inbound mail not originating from approved IP ranges or lacking the X-MS-Exchange-Organization-AuthAs: Internal header.
Organizations should also disable Direct Send to block internal sender spoofing and validate their full configuration using the free testing tool. Mitigations can take up to an hour to propagate fully after being applied.
Microsoft was first notified on April 21, 2026, but MSRC closed the report as a non-vulnerability. With no vendor fix on the horizon, the responsibility for remediation falls entirely on Exchange Online administrators.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.