← Home

Bought for $15, 'No-Reply' Domains Leak Corporate Secrets by the Hundred-Thousand

For years, thousands of organizations have quietly performed the digital equivalent of hiding a house key under a welcome mat that reads "nobody lives here." The key, in this case, is the no-reply@ address — the dead-end mailbox that companies create for automated mail they assume no human will ever read. That assumption has now been proven dangerously wrong, and a couple of security researchers have been collecting the evidence.

Security researcher Cory Solovewicz and a colleague bought a handful of cheap, generic domains the email industry had effectively orphaned. Among them were noreply.net and deleteduser.com — the kind of address an automated system invents, uses once and then forgets. By pointing those domains at mail-listening infrastructure, Solovewicz effectively opened a mailbox for traffic the entire corporate world had written off as unreachable. It was not unreachable. It arrived.

The numbers, reported by Wired and echoed by Digital Trends and SC Media, are startling. Solovewicz's noreply.net — the largest domain he controls — has absorbed roughly 400,000 messages in the year and a half he has owned it, nearly 30,000 of them carrying attachments. noreply.us alone pulled in tens of thousands of messages across several years. His colleague, Mike Sheward, spent around $15 on deleteduser.com, a name systems invent when an employee record is erased, and received mail from three separate organizations within the first hour.

Inside that mail was corporate treasure of the rawest kind: credentials and login details, HR and personnel files, internal documents and stills pulled from CCTV systems. Hundreds of companies, apparently convinced their no-reply addresses were sealed dead ends, have been routing sensitive material straight into a stranger's hands — no hacking, no phishing, no exploit involved. Just a mailbox nobody bothered to delete.

The sheer scale points to a systemic failure rather than a handful of sloppy admins. Solovewicz probed more than 7,000 similar placeholder domains and found 328 configured with catch-all inboxes, suggesting the true problem may dwarf anything uncovered so far. The uncomfortable conclusion is that the no-reply convention is not a convenience at all. It is a standing security liability — a permanently open door with no guard on it.

It also belongs to a broader email-hygiene failure that includes spoofing and weak DMARC enforcement. Plenty of organizations still lack proper sender validation, so mail is treated as more trustworthy than it deserves, both on the way out and on the way in. A domain that should be configured to reject everything instead quietly accepts whatever lands in it, watched by nobody. Every one of those messages was sent in good faith to a destination the sender believed did not exist — a faith that turned out to be profoundly misplaced.

The fix is about as glamorous as a filing cabinet: verify MX records, lock or delete dormant domains, and never point real data at an address designed never to be read. None of it is technically hard. It only requires companies to stop assuming the void is empty.

The next message a company routes to a "no-reply" address may well be its most sensitive file — delivered, by design, to whoever happens to be listening. Until organizations start treating email like the infrastructure it is, that listener will keep filling inboxes the world agreed were empty.

Sources: Wired, Digital Trends, SC Media

✓ Independent sources cross-checked and verified before publishing