This doesn't seem correct, if Microsoft truly does not do so in this scenario then it's impossible for it not to have been known by many many thousands of people well before 2023.
There's nothing inconsistent with that. Spear fishing techniques that rely on a number of bad practices, where thousands of people know what's wrong, survive as long as high volume spam is largely frustrated by post fact remediation, i.e. forcing some domain to disable open forwarding or suspending some account on too much of it.