Recently the #MSExchange product group posted an article on disabling #SMTP Direct Send and after feedback reposted it with some additional clarifications because there were some misconceptions on the definition. I have had similar discussions with organizations. It depends on your configuration what the impact might be, but IMHO it is a welcome option to reduce your attack surface but you obviously need to understand it correctly.

#WeekITtip #Security #SMTP #Mail #Microsoft365

Direct Send is defined as your organization sending mail to #MSExchange Online using a sender domain that is an accepted domain AND which is not send via any authentication (user or via Connectors). In some cases you might require this functionality, however this obviously can open your organization up to receive spoofed mails. Those should be filtered, but depending on the complexity the ability to disable Direct Send is a welcome option.

#WeekITtip #Security #SMTP #Mail #Microsoft365

If you are responsible for your orgs mail infrastructure, definitely read this post and evaluate the impact of disabling Direct Send: https://techcommunity.microsoft.com/blog/exchange/direct-send-vs-sending-directly-to-an-exchange-online-tenant/4439865?wt.mc_id=M365-MVP-5000976

#WeekITtip #Security #SMTP #Mail #Microsoft365

Direct Send vs sending directly to an Exchange Online tenant | Microsoft Community Hub

This post discusses what Direct Send is, is not, and how to help control email sent directly to your tenant.

TECHCOMMUNITY.MICROSOFT.COM