spf dkim dmarc

  1. MOERA Outbound Cap: 100 External Recipients per 24h for onmicrosoft.com

    Microsoft is imposing a hard limit on outgoing email from free “.onmicrosoft.com” (MOERA) tenant domains to combat widespread abuse and protect delivery for legitimate Microsoft 365 customers, and the change — which takes effect in staged waves starting October 15, 2025 for trials — restricts...
  2. CVE-2025-25007: Exchange Server Spoofing - Quick Mitigation Guide

    Microsoft’s security portal lists CVE-2025-25007 as a Microsoft Exchange Server spoofing vulnerability caused by improper validation of syntactic correctness of input, but public technical detail and third‑party analysis for this specific CVE remain sparse at the time of publication —...
  3. Microsoft 365 Direct Send Phishing: How Attackers Impersonate Internal Users & How to Protect Your Organization

    A new wave of targeted phishing attacks is sweeping through organizations, exploiting a legitimate Microsoft 365 feature to wreak havoc from inside the trusted walls of enterprise email. Security researchers have recently uncovered threat actors using the Microsoft 365 “Direct Send” capability...
  4. Microsoft 365 DNS Misconfiguration Disrupts OTP Email Delivery: Lessons & Prevention

    For many organizations relying on Microsoft 365, even brief interruptions to core service components can have a ripple effect on productivity, security, and trust. Recently, Microsoft was forced to confront yet another challenge related to the Domain Name System (DNS)—a core pillar of internet...
  5. Protect Your Organization: Combating Phishing Attacks Exploiting Microsoft 365's Direct Send

    In recent months, a sophisticated phishing campaign has exploited Microsoft 365's "Direct Send" feature, targeting over 70 organizations, primarily in the United States. This attack method allows cybercriminals to impersonate internal users and deliver phishing emails without compromising...
  6. Securing Microsoft 365 Against Phishing Exploiting Direct Send Vulnerability

    A sophisticated phishing campaign has been exploiting Microsoft 365's Direct Send feature, targeting over 70 organizations across various sectors in the United States since May 2025. This attack underscores the evolving tactics of cybercriminals and highlights the need for organizations to...