Hackers Can Read Your 'No Reply' Emails—This Guy Bought the Domains to Prove It

Sensitive Info Goes into 'No Reply' Emails Constantly. This Guy Sees It All

Hackers Can Read Your 'No Reply' Emails—This Guy Bought the Domains to Prove It

Security researcher Cory Solowewicz bought the domains noreply.us and noreply.net as a privacy experiment, only to discover that hundreds of companies were inadvertently sending sensitive emails—including injury reports, pizza orders, and test credentials—to these addresses. He and fellow researcher Mike Sheward, who purchased deleteduser.com, have received hundreds of thousands of messages, exposing a systemic flaw in how companies handle email addresses for departed users. They've been notifying affected organizations and warn that the problem is far larger than they can handle alone.

I created an accidental honeypot. I had no idea it was going to turn into this.
  1. telesilla

    I have a very early Gmail account I still use which collects an unbelievable amount of other people's emails who cannot be bothered to fill out a form correctly, hotel reservations, insurances. I could cancel them all easily and mess with people but I delete and move on.

    It's easy to be a bad actor given the conditions that the internet was built on.

  2. mcc1ane

    https://archive.is/xn3gW

  3. sparkling

    There was a CCC talk with a similar approach, where researches bought expired government domains and typo / bit flip domains. For example: bund.de is managed by the German Federal Government and they purchased bund.ee, the Estonian TLD, which is both a typo and bit flip and started watching email and DNS requests coming in.

    German language only unfortunately https://media.ccc.de/v/39c3-verlorene-domains-offene-turen-w...

More from this day

2026-08-08