{"success":true,"data":{"id":"m365-direct-send-internal-spoof","label":"M365 Direct Send internal spoof — From-domain == To-domain + Outlook relay + SPF/DKIM/DMARC fail (Varonis 2025)","description":"Email appears to come from inside the recipient's own tenant (From-domain matches recipient domain OR sender address literally equals recipient address) and was routed via tenantname.mail.protection.outlook.com, but Authentication-Results shows SPF/DKIM/DMARC fail. Attackers abuse Microsoft 365 Direct Send smart-host to deliver spoofed-internal phishing that bypasses most anti-impersonation logic because the email is technically relayed through a \"trusted\" Microsoft endpoint. Varonis documented an active campaign impacting 70+ organizations since May 2025 (PowerShell-delivered PDF+QR credential phishing).","tier":"danger","category":"scam","isThin":false}}