TL;DR: Attackers are abusing Microsoft Direct Send to bypass secure email gateways and deliver QR code and CAPTCHA-hidden payloads directly to inboxes without stolen credentials, according to Abnormal AI. The pattern shows that trusted infrastructure can become a delivery path that legacy email defenses do not reliably inspect.
Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “Microsoft 365 Direct Send Abuse: When Trusted Infrastructure Turns Malicious”.
Key questions
Q: Where does trusted email abuse fail in practice?
A: It fails when defenders equate a trusted delivery path with a trustworthy message.
Q: Why do QR codes and CAPTCHA-hidden payloads increase email risk?
A: They shift malicious intent out of plain text and into forms that reduce the effectiveness of standard text, URL, and attachment inspection.
Practitioner guidance
- Harden trusted mail paths Classify platform-native delivery paths such as Microsoft Direct Send separately from ordinary inbound mail and apply explicit risk scoring to them.
- Detect concealed payload techniques Add detection logic for QR codes, CAPTCHA-gated links, and lookalike domains because those techniques reduce the value of text-based inspection.
- Re-evaluate secure email gateway assumptions Test whether your secure email gateway actually inspects messages that arrive through trusted infrastructure or whether it implicitly exempts them.
Bottom line: Trusted email routes can become delivery paths for malicious content when controls assume the platform context is safe by default.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Trusted-infrastructure abuse creates an email security blind spot. Microsoft Direct Send is not the problem by itself. The problem is that defenders often assign a lower risk score to messages that arrive through native platform paths, even when the payload is clearly adversarial. That turns trust in the delivery mechanism into a detection weakness, and the practical conclusion is that routing trust cannot be treated as content trust.
A question worth separating out:
Q: What should organisations do when a mail control assumes native delivery is safe?
A: Treat that assumption as a policy defect, not a tuning issue. Reclassify the delivery path, verify which inspection stages still run, and confirm whether users can receive malicious payloads through the trusted route without triggering the same response workflow used for external phishing.
👉 Read our full editorial: Microsoft Direct Send abuse exposes the limits of trusted email