A researcher bought noreply.net. Companies started sending him secrets.

A researcher bought noreply.net. Companies started sending him secrets.

Companies treat some email domains as digital trash cans, despite the risks.

Written by OutOfToken AI

August 10, 2026 · 4 min read · Synthesized from reporting by Ars Technica · How this works

AI Verified · 8/10

Cory Solovewicz didn't hack anyone. He just bought a domain name that hundreds of companies had already decided was disposable. What arrived in his inbox afterward reads like a masterclass in corporate carelessness — internal alerts, password resets, and other sensitive correspondence that was never supposed to leave the building.

An accidental honeypot

Solovewicz, a security researcher, purchased noreply.us in 2020 and followed it up with noreply.net in 2024. The first was meant as a catch-all address for a privacy experiment. What he found instead was that automated systems at real companies were resolving these placeholder-sounding domains and firing off live email to them.

The scale of the leak

One of Solovewicz's domains has logged more than 401,000 emails since he set it up, according to reporting from WIRED. He describes the situation not as an intrusion but as an accident of infrastructure — his mail servers simply answered when companies' systems came knocking, because the domain existed and nobody was checking who owned it.

"One domain alone has funneled over 401,000 emails to a researcher who never asked for them."

Why 'noreply' isn't neutral

The pattern behind this is mundane and that's exactly the problem. Developers routinely hardcode placeholder addresses like noreply@ or deleteduser@ into scripts, templates, and automated workflows, assuming the domain is inert or symbolic rather than a real, ownable piece of internet infrastructure. When someone else registers that domain, every misconfigured system that references it becomes an unwitting data pipe straight to a stranger.

A breach by any other name

Security professionals are blunt about how this should be classified: sending sensitive data to the wrong recipient via email is a data breach, intentional or not. It doesn't matter that no one broke a firewall or exploited a vulnerability in the traditional sense — corporate secrets ended up in the hands of someone outside the organization, which is the actual definition that regulators and incident-response teams care about.

Fixing this doesn't require exotic security spending — it requires companies to stop treating placeholder domains as symbolic and start treating them as real addresses someone might own. Until that habit changes, researchers like Solovewicz will keep functioning as accidental collection points for the internet's sloppiest engineering decisions, and the next person to register a domain like this one might not be publishing a write-up about it.

Editorial Note

The WIRED article (Source 1) provides direct corroboration of the core narrative: Solovewicz's domain purchases, the volume of emails received, and the accidental honeypot mechanism. Sources 3 and 5 confirm the legal and security classification of misdirected sensitive emails as data breaches. The research does not address the broader claim about developer practices, but all verifiable factual claims about Solovewicz's actions and the data volumes check out.

Data Breach Alert

Claim Tracker

AI-assessed

VerifiedCory Solovewicz purchased noreply.us in 2020 and noreply.net in 2024

Source 1 (WIRED) and Source 2 confirm both domain purchases and years.

VerifiedOne of Solovewicz's domains has logged more than 401,000 emails

Source 1 (WIRED) states 'Since December 2024, one of the domains' received this volume. Source 2 mentions '401,79[x]' emails registered to one domain.

VerifiedSolovewicz initially intended noreply.us as a catch-all address for a privacy experiment

Source 2 confirms he 'initially intended to use noreply.us as a catch-all address for a privacy experiment.'

VerifiedSending sensitive data to the wrong recipient via email is classified as a data breach

Source 3 explicitly states 'sending sensitive data via email to the wrong person is a data breach' and Source 5 describes misdirected sensitive external emails as 'a data loss incident.'

UnverifiedDevelopers routinely hardcode placeholder addresses like noreply@ into scripts and templates

The research confirms that companies are sending to these domains and that the problem exists, but does not directly verify the claim about how widespread hardcoding of these placeholders is among developers.

Ask AI about this story

// discussion

sign in to join the discussion