Sensitive Info Goes into 'No Reply' Emails Constantly. This Guy Sees It All

Turns out companies keep blasting private details into inboxes they think nobody reads

TLDR: A researcher bought “no-reply” web addresses and discovered companies were sending him thousands of private emails meant for no one. Commenters were split between “this has always been broken” and “it’s wild the internet still works at all without more people abusing this.”

A security researcher accidentally became the internet’s most cursed mailbox after buying noreply.us and noreply.net—and suddenly started receiving a torrent of other people’s sensitive emails: repair requests, school account setups, injury reports, even pizza orders. The big gasp from readers wasn’t just “how is this real?” but “wait, this has been happening forever?” One commenter immediately pulled receipts with an archived link, while others said this is basically an old internet horror story in new packaging.

The comment section quickly turned into a mix of war stories, dark jokes, and low-key panic. One person pointed to a German hacker conference talk where researchers bought lookalike government web addresses and just watched the mistakes roll in, which really amped up the “this problem is everywhere” energy. Another chimed in with the history lesson that even example.com used to get this kind of accidental junk until official internet rules shut that down. Translation for non-nerds: people and computer systems have apparently been firing private messages into the void for years.

But the spiciest mood came from everyday users saying, basically, “oh, I’ve seen this too.” One early Gmail user claimed they still get random strangers’ hotel bookings and insurance emails and could easily cause chaos—but don’t. That’s where the real drama lands: the internet is running on a shocking amount of good behavior and luck, and commenters were equal parts amused, horrified, and amazed more people haven’t gone full villain.

Key Points

  • Cory Solovewicz says domains he owns, including noreply.net and noreply.us, have received hundreds of thousands of unintended automated emails containing private and operational information.
  • The messages include items such as injury reports, pizza order confirmations, service orders, account setup emails, and test platform credentials.
  • Solovewicz bought the domains for personal use, then discovered they functioned as an accidental honeypot because organizations were sending to placeholder-style addresses they assumed were unmonitored.
  • He has been contacting affected organizations and presented the issue at Defcon, arguing the data could have been exploited if the domains had been acquired by malicious actors.
  • The article says the problem is longstanding and avoidable, with internal domains or the .invalid domain cited as safer alternatives to public placeholder domains.

Hottest takes

"I could cancel them all easily and mess with people" — telesilla
"researches bought expired government domains and typo / bit flip domains" — sparkling
"Same thing with the example.com domain until RFC 2606 put an end to it" — throwa356262
Made with <3 by @siedrix and @shesho from CDMX. Powered by Forge&Hive.