An invoice lands in your accounts inbox on a Tuesday morning. It’s from a supplier you’ve paid a dozen times. The sender address is exactly right. Open it in Outlook and the sender’s name and even their profile photo appear, the same as always. The email says their bank has changed and gives new account details for this month’s payment.
Nobody at the supplier sent it. Nobody’s account was hacked. No password was stolen. And yet the message passed straight into the inbox, looking indistinguishable from the real thing.
That’s the scenario behind a Microsoft 365 weakness that security researchers have named Ghost Sender. We received an advisory about it this week, and because so many of the businesses we work with run their email on Microsoft 365, it’s worth explaining in plain terms what it is, who it affects, and what actually needs doing about it.
What Ghost Sender actually is
First, the reassuring part: Ghost Sender is not a virus, and it isn’t a flaw that lets someone break into your mailbox. It’s a configuration problem. It only exists when one particular setting in a Microsoft 365 tenant has been left in the wrong state, and it can be closed completely once that setting is corrected.
Here’s the mechanics, without the jargon. Many businesses don’t let email arrive at Microsoft 365 directly. Instead, incoming mail is pointed first at a filtering service — a spam and threat scanner that sits in front of the mailbox, checks each message, and passes the clean ones through to Microsoft. That “check it first” service is what your domain’s MX record advertises to the world as the front door.
The problem is that Microsoft 365 also has a second door round the back — a direct delivery address for your tenant that exists whether you use it or not. Ghost Sender is the discovery that an attacker can walk up to that back door and hand over a message directly, skipping the filtering service entirely. If the tenant hasn’t been told to be strict about who’s allowed to use that back door, it accepts the message and drops it into the inbox.
The uncomfortable detail is what happens to the usual safety checks. Email has three well-known anti-forgery standards — SPF, DKIM and DMARC — that are supposed to catch exactly this kind of impersonation. In the researchers’ testing, the forged messages failed all three checks and were still delivered to the inbox, with no warning shown to the person reading them. The failure was recorded, but it wasn’t enforced.
Why this matters for how a business runs day to day
A spoofing weakness sounds abstract until you map it onto the emails a business actually acts on. The danger of Ghost Sender is that it lets an attacker send mail that appears to come from anyone — an outside supplier, a bank, a well-known software provider, or someone inside your own organisation.
That last one is the sharp end. Because the message is delivered as if it originated inside the tenant, Outlook can resolve the fake internal sender the same way it resolves a real colleague — pulling up the correct name and, in many cases, the actual profile photo. An email that looks like it’s from your managing director, complete with their picture, asking accounts to rush a payment through before end of day, is a very different thing to defend against than an obvious scam from a stranger.
The practical risks fall into a few familiar buckets:
- Invoice and payment fraud. A message that appears to come from a genuine supplier, asking you to update their bank account details. This is the single most expensive form of business email fraud in New Zealand, and Ghost Sender makes the fake far more convincing.
- Impersonation of the boss. A request from “the director” or “the owner” to approve a transfer, buy gift cards, or release payroll information — landing with the real internal identity attached.
- Credential and data phishing. A note that looks like it’s from Microsoft, your bank, or a trusted vendor, steering staff to a fake login page or asking them to hand over information.
- Reputational exposure. Your own domain being used to send convincing fakes to your customers and partners, with the forgery appearing to come from inside your business.
None of these require the attacker to be sophisticated. They require the attacker to be believable — and Ghost Sender hands them believability for free.
Are you affected?
The exposure applies to businesses that run email on Microsoft 365 (or Exchange Online in a hybrid setup) and route their incoming mail through an external filtering or gateway service before it reaches Microsoft. That’s an extremely common arrangement — it’s exactly how most businesses that take email security seriously have things set up.
The good news, and the point worth holding onto, is this: the weakness only opens up when the back door is left unguarded. The correct setup closes it. If your Microsoft 365 environment was configured by someone who knows to lock down direct-to-tenant delivery — the way a properly built mail-filtering setup should be — you are very likely already protected, and no drama is required.
There’s also a detail that’s easy to get wrong, and it’s the one worth double-checking. The setting that locks the back door has to apply to all sending domains, not just the domain of the filtering service you use. If it’s been narrowed to a single provider, forged mail from every other domain still gets through despite the restriction being “in place”. A configuration that looks done can still leave the gap open.
What to do about it
The fix lives in the Microsoft 365 admin settings, not in anything your staff need to install or change on their computers. In broad terms, closing Ghost Sender means making sure the tenant refuses unauthenticated mail that arrives at the back door instead of coming through your filtering service. In practice that’s a combination of the right connector configuration, a mail-flow rule that quarantines anything trying to skip the approved route, and confirming the whole thing actually behaves as intended rather than just looking correct on the settings page.
If you’d like certainty rather than a “probably fine”, the sensible steps are:
- Confirm how your mail is set up. If you’re on Microsoft 365 with an external spam filter or gateway in front of it, you’re in the group this applies to.
- Have the tenant’s inbound configuration checked — specifically whether direct-to-tenant delivery is being rejected, and whether that restriction covers all domains rather than just one.
- Verify the behaviour, don’t just trust the settings. The only reliable proof is testing whether a message that skips the filter is actually blocked.
- Keep SPF, DKIM and DMARC in place. They remain essential — Ghost Sender is a reminder that they only protect you when the environment is set up to enforce their results, not a reason to abandon them.
This is exactly the kind of thing worth checking rather than assuming. If you’re a client of ours and your email runs through us, we can confirm your configuration and put your mind at rest. If you’re running Microsoft 365 elsewhere and you’re not sure whether your back door is locked, get in touch and we’ll help you find out — it’s a short check, and it’s a far better use of an afternoon than untangling a fraudulent payment after the fact.
Ghost Sender was documented publicly by independent security researchers in mid-2026. This article summarises the practical implications for business owners; the underlying technical research is available through security vendors covering the issue.
Was this of value to you? If so and you feel the desire: Buy Me A Coffee