BusinessCybersecurityNewswireTechnology

Why You Should Never Put Sensitive Info in ‘No Reply’ Emails

Originally published on: August 8, 2026
▼ Summary

– Security researcher Cory Solovewicz has received over 400,000 emails at his domains noreply.us and noreply.net, which he bought in 2020 and 2024, respectively.
– The emails contain other people’s private information and company secrets, such as injury reports, pizza orders, and service requests, sent inadvertently by misconfigured company systems.
– Solovewicz calls his domains an “accidental honeypot” because companies send sensitive data to @noreply addresses, assuming they are unmonitored or non-existent.
– He presented his findings at the Defcon security conference and is alerting affected companies to fix their system errors, without publicly naming them.
– Similar issues are not new; researcher Mike Sheward bought the domain deleteduser.com and received sensitive emails within an hour, highlighting a broader, avoidable problem with misconfigured email systems.

Receiving a firehose of other people’s private data is a reality for security researcher Cory Solovewicz. Since December 2024, a single domain he owns has logged 401,796 incoming messages, averaging roughly 700 pings per day. This isn’t a typical spam flood. Instead, companies are unintentionally leaking sensitive information, including injury reports from a city government, pizza order confirmations, and school platform account credentials, directly to his inbox. “I get service orders for people that need repairs. I get lots of test platform credentials,” says Solovewicz, a security researcher and consultant.

The root of this data leak lies in his ownership of the domains noreply.us and noreply.net, which he acquired in 2020 and 2024, respectively. Initially, he planned to use noreply.us as a catch-all email address to filter messages and boost his own privacy. He quickly noticed, however, that other systems were sending mail to @noreply.us addresses. “I created an accidental honeypot,” Solovewicz tells WIRED. “I had no idea it was going to turn into this.”

Organizations appear to be sending emails to addresses like [companyname]@noreply.net under the false assumption that these messages go nowhere and cannot be monitored. It’s also plausible that systems are converting a person’s individual email address to one of these placeholder domains when an employee leaves a company or an account is deleted.

What began as a personal email project has morphed into a large-scale effort to warn businesses about their misconfigured internal systems. Solovewicz, who presented his findings at the Defcon security conference yesterday, says he is ultimately relieved that he, rather than a malicious actor or nation state, ended up with these domains. “I did not realize that this was going to be as big of a problem as it is,” he says, choosing not to publicly name the affected entities. He has been actively alerting companies to their errors, encouraging them to audit and fix their systems. “I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff.”

The scale of the issue is significant. The noreply.net domain, his largest, has received 400,000 messages over the year and a half he has owned it, with 28,365 of those containing attachments. The noreply.us domain has received 37,255 messages over 2,345 days since his 2020 purchase. In the month leading up to his conference talk, the two domains combined received more than 11,000 messages. The emails originate from over 14,000 “from” addresses across 6,200 root domains, and all are automated by company systems rather than written by humans.

While this problem isn’t new, nearly 20 years ago independent security journalist Brian Krebs wrote about companies sending millions of messages to @donotreply.com emails, it is inherently avoidable. Companies could easily use internal domains or the .invalid domain, which is guaranteed not to exist.

Solovewicz isn’t alone in this voluntary effort to protect corporate data. Earlier this year, Mike Sheward, the head of security at EV charging company Xeal, spent about $15 to buy the domain deleteduser.com. “Within the first hour, there were three different organizations that had emailed stuff to @deleteduser.com,” Sheward tells WIRED, noting that companies seem to be simply changing email addresses rather than completely deleting accounts from their systems.

(Source: Wired)

Topics

email security 95% data breaches 93% domain misconfiguration 91% honeypot systems 88% security research 86% privacy protection 84% corporate responsibility 82% automated emails 80% incident response 75% email infrastructure 73%
Show More