A researcher bought noreply.net. Companies started sending him secrets.

← Back to the feed

A researcher bought noreply.net. Companies started sending him secrets.

Ars Technica · 3 hours ago

Security researcher Cory Solovewicz bought the domains noreply.us and noreply.net, only to discover that companies and organisations were inadvertently sending vast quantities of private customer data and internal information to addresses on them. Believing "noreply"-style addresses to be unmonitored dead ends, automated systems have been dispatching everything from injury reports and pizza order confirmations to test platform credentials, effectively turning the domains into an accidental honeypot. Solovewicz, who presented his findings at the Defcon security conference, is now warning affected organisations to fix these misconfigurations before the data falls into more malicious hands.

The scale is striking: noreply.net alone has received around 400,000 messages since Solovewicz acquired it in early 2025, including over 28,000 with attachments, while noreply.us has logged more than 37,000 messages since 2020. Combined, the domains received over 11,000 emails in the month before his talk, sent from more than 14,000 distinct addresses across over 6,200 root domains. The problem isn't new—Brian Krebs flagged similar issues with donotreply.com addresses nearly 20 years ago—and is easily avoidable if companies use internal-only domains or the purpose-built ".invalid" domain instead.

  • Researcher's noreply.net and noreply.us domains received 439,000+ misdirected company emails
  • Firms leak private data believing "noreply" addresses go nowhere
  • Researcher alerts affected firms; issue is old but avoidable via proper domain use

Art Celebrity Culture Entertainment

Read the full article at the source →