A researcher bought noreply.net. Companies started sending him secrets.
Companies treat some email domains as digital trash cans, despite the risks.
Written by OutOfToken AI
August 10, 2026 · 4 min read · Synthesized from reporting by Ars Technica · How this works
Cory Solovewicz didn't hack anyone. He just bought a domain name that hundreds of companies had already decided was disposable. What arrived in his inbox afterward reads like a masterclass in corporate carelessness — internal alerts, password resets, and other sensitive correspondence that was never supposed to leave the building.
An accidental honeypot
Solovewicz, a security researcher, purchased noreply.us in 2020 and followed it up with noreply.net in 2024. The first was meant as a catch-all address for a privacy experiment. What he found instead was that automated systems at real companies were resolving these placeholder-sounding domains and firing off live email to them.
The scale of the leak
One of Solovewicz's domains has logged more than 401,000 emails since he set it up, according to reporting from WIRED. He describes the situation not as an intrusion but as an accident of infrastructure — his mail servers simply answered when companies' systems came knocking, because the domain existed and nobody was checking who owned it.
"One domain alone has funneled over 401,000 emails to a researcher who never asked for them."
Why 'noreply' isn't neutral
The pattern behind this is mundane and that's exactly the problem. Developers routinely hardcode placeholder addresses like noreply@ or deleteduser@ into scripts, templates, and automated workflows, assuming the domain is inert or symbolic rather than a real, ownable piece of internet infrastructure. When someone else registers that domain, every misconfigured system that references it becomes an unwitting data pipe straight to a stranger.
A breach by any other name
Security professionals are blunt about how this should be classified: sending sensitive data to the wrong recipient via email is a data breach, intentional or not. It doesn't matter that no one broke a firewall or exploited a vulnerability in the traditional sense — corporate secrets ended up in the hands of someone outside the organization, which is the actual definition that regulators and incident-response teams care about.
Fixing this doesn't require exotic security spending — it requires companies to stop treating placeholder domains as symbolic and start treating them as real addresses someone might own. Until that habit changes, researchers like Solovewicz will keep functioning as accidental collection points for the internet's sloppiest engineering decisions, and the next person to register a domain like this one might not be publishing a write-up about it.
Editorial Note
The WIRED article (Source 1) provides direct corroboration of the core narrative: Solovewicz's domain purchases, the volume of emails received, and the accidental honeypot mechanism. Sources 3 and 5 confirm the legal and security classification of misdirected sensitive emails as data breaches. The research does not address the broader claim about developer practices, but all verifiable factual claims about Solovewicz's actions and the data volumes check out.
Claim Tracker
AI-assessed
Source 1 (WIRED) and Source 2 confirm both domain purchases and years.
Source 1 (WIRED) states 'Since December 2024, one of the domains' received this volume. Source 2 mentions '401,79[x]' emails registered to one domain.
Source 2 confirms he 'initially intended to use noreply.us as a catch-all address for a privacy experiment.'
Source 3 explicitly states 'sending sensitive data via email to the wrong person is a data breach' and Source 5 describes misdirected sensitive external emails as 'a data loss incident.'
The research confirms that companies are sending to these domains and that the problem exists, but does not directly verify the claim about how widespread hardcoding of these placeholders is among developers.
Ask AI about this story
// discussion
sign in to join the discussion
