LAS VEGAS — A security researcher who bought the internet domains noreply.net and noreply.us says companies and public organizations have mistakenly sent them hundreds of thousands of automated messages containing customer information, attachments and internal credentials.
Cory Solovewicz presented the findings at the Def Con security conference. He said noreply.net received more than 400,000 messages over roughly a year and a half, including 28,365 with attachments. Noreply.us received more than 37,000 messages after he acquired it in 2020. Senders used more than 14,000 addresses across about 6,200 root domains.
The messages were not ordinary spam. Solovewicz said they included municipal injury reports, repair orders, school-platform account messages, test credentials and customer purchase confirmations. Organizations apparently substituted addresses at “noreply” domains when deactivating accounts or assumed that such addresses could not be monitored.
A second researcher, Mike Sheward, reported similar results after buying deleteduser.com for about $15. He received vacation approvals, hotel bookings, health-product orders, meeting invitations and workplace-safety images. The researchers said they have acquired more than 30 likely placeholder domains to keep them away from malicious operators.
The problem is preventable. Systems can use an internal domain that is not routed to the public internet or the reserved .invalid top-level domain when a placeholder is required. Companies also should delete or disable old routing rules, test automated notifications and avoid rewriting former employees’ addresses to publicly registrable domains.
Solovewicz said he has tried to notify affected organizations, with mixed results. He did not publicly identify most of them, limiting independent verification of individual examples, but the message totals and recurring pattern point to a broader risk: an email address that looks disposable may belong to someone.
Sources: Ars Technica, Wired and Def Con reporting. Published Aug. 10, 2026.
