Imagine checking your inbox and finding 700 emails waiting for you every single day—not from friends, family, or even the usual marketing newsletters, but a chaotic, private stream of other people’s most sensitive data. This is the reality for security researcher Cory Solovewicz, who, since December 2024, has been the unwilling recipient of over 400,000 messages sent to the domains “noreply.us” and “noreply.net.” While most of us treat “noreply” email addresses as digital dead-ends, Solovewicz’s ownership of these specific domains has turned them into a massive, accidental “honeypot.” Instead of the silence one might expect, he finds himself reading injury reports from city governments, private pizza orders, and, more alarmingly, credentials and internal setup guides meant for secure corporate systems.
The root of this problem lies in a dangerous combination of corporate laziness and poor system architecture. Many companies, laboring under the false assumption that sending an email to a “noreply” address is a safe way to dispose of data, use these domains as a digital “black hole” for automated notifications or as placeholders when a user leaves the company. They treat these addresses like trash cans that never get emptied, never stopping to consider who might eventually register those domains. When Solovewicz purchased them, he initially intended to use them for personal privacy filters, but he quickly realized he had inherited a digital dumping ground for thousands of organizations that had simply misconfigured their backend systems, inadvertently leaking company secrets and customer privacy into the hands of a stranger.
What has followed for Solovewicz is an unexpected, full-time crusade to protect companies from their own incompetence. Rather than exploiting the data, he has spent his time cataloging the leaks and reaching out to the thousands of impacted entities to warn them of their security gaps. Presenting his findings at the Defcon security conference, he highlighted the sheer scale of the issue: over 6,200 unique root domains are currently funneling automated, sensitive traffic into his inbox. It is a sobering look at how automated systems, when left unmonitored, can create a continuous flow of data that leaves businesses exposed. He notes that he is lucky to be the one who owns these domains; had they fallen into the hands of a malicious actor or a nation-state entity, the consequences for these companies and their users could have been catastrophic.
The problem isn’t new, but it remains remarkably stubborn. Nearly two decades ago, journalists identified that organizations were firing millions of emails into the abyss of unowned “donotreply” domains, yet the practice persists today. Companies continue to use these addresses for legitimate business processes, and when a system fails or a user is removed, the automated software blindly continues to fire off emails to an address that, to the system’s logic, “should” exist but is actually owned by a private individual. This behavior isn’t just a technical glitch; it is a systemic failure to audit how data is managed when it is supposed to be discarded.
Solovewicz is not the only researcher highlighting this vulnerability. Others, like Mike Sheward, have conducted similar experiments, such as purchasing the domain “deleteduser.com,” only to be flooded with sensitive internal correspondence within an hour. These researchers are essentially performing a public service, proving that companies are often not truly deleting accounts or properly managing their outgoing communication streams. They are merely swapping one email address for a placeholder, hoping the problem disappears. The recurring message from these researchers is clear: stop using public-facing domains for internal housekeeping and start using reserved domains like “.invalid,” which are specifically designed to be unreachable and safe.
Ultimately, the story of Solovewicz’s inbox is a wake-up call regarding the fragility of modern data infrastructure. It forces us to ask: if these companies don’t know where their “noreply” mail is going, what other security holes are they ignoring? Solovewicz isn’t asking for recognition or profit; he is asking for the bare minimum of digital hygiene. He wants organizations to take responsibility for their own data, audit their automated systems, and stop treating the internet like an infinite, secure trash can. Until companies learn to clean up their own digital footprints, researchers like him will remain the only thing standing between private citizen data and the vast, unmonitored sprawl of the web.