Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
Security researcher Cory Solovewicz has inadvertently become the recipient of hundreds of thousands of emails containing other people’s personal data and corporate information after buying the domains noreply.us and noreply.net. Organisations appear to send automated messages to placeholder-style addresses they assume are unmonitored, exposing information such as injury reports, repair requests, order confirmations and test credentials. The case highlights how poorly configured email systems can create avoidable data-security risks.
Since December 2024, noreply.net has received about 401,796 messages—roughly 700 a day—including 28,365 attachments; noreply.us has received 37,255 messages since 2020. Together, the domains received more than 11,000 emails in the month before Solovewicz’s Defcon presentation, from over 14,000 sender addresses across 6,200 root domains. He is privately notifying affected organisations and says they could prevent such errors by using internal domains or the reserved .invalid domain.
- Misconfigured systems are sending sensitive automated emails to publicly owned “no reply” domains.
- One researcher received roughly 402,000 messages through noreply.net.
- The problem is longstanding but readily avoidable.