Is M365 Direct Send just the normal internet SMTP port?

Posted by jsellens@reddit | sysadmin | View on Reddit | 21 comments

I feel like I must be missing something, because it "obviously" can't be this.

In relation to recent spam/phishing campaigns, I've seen a number of people recommend that folks should disable M365 "Direct Send". Which according to the documentation is some magic feature where you can send mail directly from simple devices to M365, using SMTP over port 25 to company.mail.protection.outlook.com which seems to me to be just ordinary everyday internet SMTP.

So is Microsoft's documentation suggesting that Direct Send is some special thing just highlighting the assumption that M365's built-in spam protection is such garbage that "everyone" will pay for a third party MX service (Barracuda, etc) that uses MAPI or a connector or something to pass inbound mail to M365?

And are the recommendations that Direct Send should be disabled, just an indication that many people set up a separate MX service, but leave the default unauthenticated internet SMTP front door wide open, thereby completely negating the utility of their special expensive MX service?

It can't really be that dumb, can it? Surely I must be missing something here?