No reply emails sensitive data is not a hypothetical search query for Cory Solovewicz. The security researcher says domains he owns, noreply.net and noreply.us, have become collection points for automated messages that organizations apparently meant to send somewhere else, including private records, internal material and attachments.
WIRED reported that Solovewicz owns the two domains and discovered the issue after configuring noreply.us as a catch-all address, meaning it accepts messages sent to any address at that domain. A label such as “no reply” is a convention for recipients, not a guarantee that an externally addressed message disappears. If the domain exists and someone controls it, it can receive mail.
Solovewicz told WIRED that noreply.net had received about 400,000 messages during the period he had owned it, including 28,365 messages with attachments. He said noreply.us had received 37,255 messages since he bought it in 2020. In the month before his Defcon presentation, he said the pair received more than 11,000 messages. The reported mail came from more than 14,000 sender addresses across 6,200 root domains and was generated by company systems rather than written by people.
The messages Solovewicz described to WIRED included city-government injury reports, pizza-order confirmations, school-platform account setup notices, repair orders and test-platform credentials. Those examples are his account, and he is not publicly naming the organizations involved.
Why can no-reply email addresses still receive messages?
“No-reply” normally signals that a company does not want recipients responding to an address. It does not reserve a domain name or make it unreachable. WIRED reported that organizations may send automated messages to placeholder-style addresses such as [email protected] under the mistaken assumption that they go nowhere. The report also said it is broadly possible that a system substitutes such an address when a person leaves an organization or deletes an account.
That distinction separates this problem from phishing. The Federal Trade Commission describes phishing as deceptive email or text meant to trick a recipient into handing over information. In this case, the reported failure is automated systems routing material to a real domain controlled by an unintended recipient.
Solovewicz said he has notified affected organizations and urged them to audit and fix their errors or misconfigurations. The problem also predates his project: WIRED noted that security journalist Brian Krebs wrote nearly two decades ago about companies sending millions of messages to donotreply.com addresses.
What can organizations use instead of public placeholder domains?
WIRED reported that internal domains or the .invalid top-level domain were possible alternatives. The standards basis is narrow but useful: RFC 2606 reserves .invalid for constructing domain names that are plainly and certainly invalid. RFC 6761 later described the framework for special-use domain names.
That is not a complete mail-system repair plan. It does underline the basic mistake: public, registrable domains are part of the internet, and treating them as a black hole for automated notifications is an avoidable gamble with other people’s data.
This story draws on original reporting from WIRED.