Security Researcher's 'No Reply' Domains Became an Accidental Trove of Company Secrets
By owning the domains noreply.us and noreply.net, security researcher Cory Solovewicz has received hundreds of thousands of automated emails containing sensitive company and personal data. He is now warning organizations about the misconfigurations behind the leaks.

Security researcher and consultant Cory Solovewicz has owned the domains noreply.us and noreply.net since 2020 and 2024, originally for personal use. Instead, he discovered that numerous organizations treat these and similar domains as unmonitored placeholder addresses—and actually send real messages to them.
Since December 2024 alone, one of his domains has logged more than 400,000 messages, averaging roughly 700 per day. The other has received over 37,000 messages since 2020. In total, mail has arrived from more than 14,000 sender addresses across 6,200 root domains, all generated automatically by company systems rather than written by people.
What ends up in the inbox
Among the material he's received: injury reports from a city government, pizza order confirmations, account setup emails from a school platform, service repair requests, and test platform login credentials. More than 28,000 of the messages included attachments.
Solovewicz detailed his findings at the Defcon security conference, saying he's relieved the domains ended up with him rather than malicious hackers or state-backed actors. He has been notifying affected companies, though many don't respond, and the scale of the problem makes reaching everyone impossible.
Not an isolated case
Mike Sheward, head of security at EV charging company Xeal, had a similar experience after buying the domain deleteduser.com, receiving emails from three organizations within the first hour. He's since received medication orders, leave-of-absence approvals, hotel bookings, and even Zoom meeting invitations from a UK government agency, plus thousands of CCTV stills from an AI company.
Both researchers have since bought more than 30 additional domains to limit the chance of malicious actors doing the same. Solovewicz has scanned over 7,000 potential placeholder domains and found 328 configured to accept any incoming mail. He urges companies to use internal domains or the dedicated .invalid domain to prevent such leaks.


