According to WIRED, security researcher Cory Solowewicz receives an unusual torrent of email: private injury reports from a city government, pizza order confirmations, school account setup messages, service orders for repairs, and test platform credentials. Since December 2024, one of the domains he controls has registered 401,796 messages, an average of 699.99 per day. The messages, he says, are automated messages from company systems that are inadvertently leaking other people's private information and company secrets.
An accidental honeypot
Solowewicz owns the catch-all domains noreply.us and noreply.net, purchased in 2020 and 2024 respectively. He originally planned to use noreply.us as a catch-all address — receiving mail for any @noreply.us address — to filter messages and protect his privacy. Other systems soon started sending mail there automatically.
"I created an accidental honeypot," Solowewicz tells WIRED. "I had no idea it was going to turn into this."
The root cause, WIRED reported, is that companies send emails to [companyname]@noreply.net or similar variations believing the messages go nowhere or cannot be monitored. Some organizations may also transform a person's individual email address into a placeholder-style domain when someone leaves or deletes their account. The result, Solowewicz says: "I get service orders for people that need repairs. I get lots of test platform credentials." The messages are automated by company systems, not written by humans, he notes.
The scale of the leak
The numbers, as reported by WIRED, show a steady stream of misdirected mail. Solowewicz says noreply.net is the largest domain he owns.
| Domain | Year purchased | Total messages | Attachments | Period |
|---|---|---|---|---|
| noreply.net | 2024 | 400,000 | 28,365 | 1.5 years |
| noreply.us | 2020 | 37,255 | — | 2,345 days |
Additionally, one of the domains has registered 401,796 messages since December 2024, and in the month before Solowewicz's conference talk the two domains combined received more than 11,000 messages. The emails have come from more than 14,000 "from" addresses and 6,200 root domains, according to WIRED.
"I did not realize that this was going to be as big of a problem as it is," Solowewicz says. He presented his findings at the Defcon security conference yesterday and says he is relieved the domains ended up under his control rather than in the hands of criminal hackers or nation states that could misuse the data.
A known and avoidable problem
The issue is not new, WIRED reported. Almost 20 years ago, independent security journalist Brian Krebs, then at the Washington Post, wrote about companies sending millions of messages to @donotreply.com addresses. The problem is also avoidable: companies could use internal domains or the .invalid domain, which is guaranteed not to exist.
Not the only one
Solowewicz is not the only researcher chasing this problem. Earlier this year, Mike Sheward, head of security at EV charging company Xeal, spent around $15 to buy the domain deleteduser.com. "Within the first hour, there were three different organizations that had emailed stuff to @deleteduser.com," Sheward tells WIRED. That suggests, WIRED reported, that companies are simply changing email addresses rather than deleting accounts outright from their systems.
What enterprises should do
Solowewicz is not publicly naming the affected entities, but he has been alerting companies to their misconfigurations. "I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff," he says. His guidance, as reported by WIRED: audit email configurations, ensure internal systems do not send automated messages to placeholder domains, and use internal-only or .invalid domains where no real recipient exists.