Security researcher uncovers massive leak of private data via misconfigured no-reply domains
Researcher Cory Solovewicz discovered that his purchased no-reply email domains are receiving thousands of unintended messages containing sensitive personal and corporate information.
Cory Solovewicz, a security consultant, bought the domains noreply.us in 2020 and noreply.net in 2024, intending to use them as a privacy tool. Instead, he found that many companies send automated messages to these placeholder addresses, unintentionally disclosing private details like city injury reports, pizza orders and internal credentials. Over the past year and a half, noreply.net alone has received roughly 400,000 messages, with thousands containing attachments, while noreply.us has logged tens of thousands of emails.
Solovewicz has been contacting the senders to alert them of the flaw, though responses have been mixed. He presented his findings at Defcon, noting that similar misconfigurations have been reported for decades and can be mitigated by using internal or.invalid domains. Other security professionals, such as Mike Sheward, have bought similar domains to capture stray emails and warn organizations, underscoring the widespread nature of the problem.
Why it matters
Misrouted automated emails can expose personal and corporate data, creating privacy and security risks for millions.
In this story