Two security researchers, working independently, have discovered that numerous organizations are inadvertently sending sensitive corporate and personal information to "no-reply" or "deleted user" email addresses. The researchers acquired several such domains and configured them to receive all incoming mail, revealing a widespread issue of system misconfigurations leading to data leakage.
Cory Solovewicz, a security researcher and consultant, purchased the domains noreply.us in 2020 and noreply.net in 2024. He initially intended to use noreply.us as a personal catch-all inbox but soon realized that automated systems were sending emails to addresses on these domains. Since December 2024, his noreply.net domain alone has received over 400,000 messages, with 28,365 containing attachments. The noreply.us domain has received 37,255 messages since its acquisition. In the month preceding his recent presentation at the Defcon security conference, Solovewicz's domains collectively received more than 11,000 messages. These emails originated from over 14,000 "from" addresses across 6,200 root domains.
The content of these emails has included injury reports from a city government, pizza order confirmations, account setup emails from a school platform, service orders for repairs, and test platform credentials. Solovewicz described his discovery as an "accidental honeypot," emphasizing that the messages are automated and not sent by human users. He expressed relief that he, rather than malicious actors, acquired these domains, and has been attempting to notify affected organizations to rectify their system errors.
Similarly, Mike Sheward, head of security at EV charging company Xeal, purchased the domain deleteduser.com for approximately $15 earlier this year. Within an hour, he began receiving emails from three different organizations. He has since accumulated thousands of unintended emails from at least 100 different organizations across multiple domains he now owns. Sheward's received emails include details of Viagra orders, requests for approval of work vacations or leaves of absence, hotel bookings with full names, and invitations to Zoom meetings from a UK government agency. He also noted receiving an invitation to a San Francisco company's summer BBQ addressed to "Dear Deleted User." A significant source of emails for Sheward is an AI company that uses object recognition to monitor worker safety at industrial sites in the Middle East, from which he has received thousands of CCTV stills.
Both researchers speculate that companies may be sending emails to these placeholder domains under the mistaken belief that they are unmonitored, or that they are transforming individual email addresses to such domains when an employee leaves or an account is deleted. The issue is not new, with similar observations dating back nearly two decades regarding @donotreply.com addresses.
Recognizing the potential for misuse by hackers, Solovewicz and Sheward have independently acquired more than 30 such domains to mitigate the risk. Solovewicz has also developed a probe to identify other potential placeholder domains configured to receive email, scanning 7,136 domains and finding 328 with catch-all inboxes. He warns that his findings may represent only a fraction of the problem.
While some organizations have quietly fixed their configurations after being notified, many have not responded, and the sheer volume of misdirected emails makes comprehensive notification a significant challenge. The researchers stress that organizations should not assume a domain is unmonitored and must audit their systems to prevent the leakage of customer, employee, and internal data.






