Who reads your noreply emails? The $15 data breach hiding in your email settings
Somebody owns noreply.net, and he reads the mail. Since taking over the domain roughly a year and a half ago, security researcher Cory Solovewicz has received about 400,000 messages there, 28,365 of them carrying attachments. None of it was addressed to him. It was not a breach — hundreds of companies are voluntarily mailing sensitive data to a stranger because of one lazy assumption: that a fake-looking email address goes nowhere.
- One researcher’s placeholder domains have absorbed over 437,000 misdirected emails, including a domain averaging roughly 700 messages per day since December 2024.
- This is old news that never got fixed: researchers captured 20 GB of Fortune 500 email in 2011, and millions of US military emails leaked to Mali’s
.mldomain through 2023. - RFC 2606 reserved
.invalid,.test,.exampleandexample.comin June 1999 precisely so placeholder addresses could never be registered by anyone. - The fix is an outbound mail log audit plus three DNS records — not a new security product.
What just happened with noreply.net?
The numbers are the story. One of Solovewicz’s domains has logged 401,796 messages since December 2024, an average he calculates at 699.99 per day. His older domain, noreply.us, purchased in 2020, has collected 37,255 messages over 2,345 days. Across his domains, mail has arrived from more than 14,000 sender addresses spanning 6,200 root domains.
He is not alone. Mike Sheward, head of security at EV charging company Xeal, spent about $15 earlier this year on deleteduser.com. Three different organizations emailed it within the first hour of him owning it. Companies were apparently overwriting departed users’ addresses with “deleteduser” and letting their systems keep sending.
Both researchers say the mail is machine-generated, not typed by humans. That matters. It means the leaks are structural — baked into CRM configs, account provisioning workflows and notification pipelines — and they will keep flowing until someone audits the config.
The stakes are now priced in dollars. The domain noreply.com is currently listed for sale at $245,000. Whoever buys it inherits the largest passive corporate data collector on the internet.
The economics here should alarm every IT leader: the attacker’s cost is a $15 domain and a catch-all mailbox, while the defender’s exposure is every automated email their systems have ever sent to an unverified address. Few attack classes have a worse cost ratio for the defense.
Is this a new problem?
No, and that is the damning part. This failure mode has been publicly documented for nearly 20 years, with each incident bigger than the last.
Brian Krebs, then at the Washington Post, reported almost two decades ago that companies were sending millions of messages to addresses at donotreply.com, a real registered domain owned by a private individual.
In September 2011, researchers Peter Kim and Garrett Gee of the Godai Group registered “doppelganger” domains that mimicked Fortune 500 subdomains — seibm.com standing in for se.ibm.com. In six months of passive collection they received more than 120,000 emails totalling 20 GB, including usernames and passwords, network architecture details, litigation documents and trade secrets. Their whitepaper found 151 of the Fortune 500, a full 30 percent, susceptible. Worse, they found doppelganger domains for major US companies already registered to entities that appeared to be based in China.
Then it went military. Johannes Zuurbier, the Dutch contractor who managed Mali’s .ml country domain, spent a decade warning US officials that emails meant for .mil addresses were landing in Mali because of a one-letter typo. In roughly six months of 2023 alone he collected about 117,000 misdirected messages, nearly 1,000 in a single day, containing medical data, base staff lists, maps of installations and the travel itinerary of the Army chief of staff, down to hotel room numbers. When his contract expired that July, control of the domain — and everything still flowing to it — reverted to Mali’s government, a close ally of Russia.
| Incident | Year | Volume | What leaked |
|---|---|---|---|
| donotreply.com (Krebs coverage) | ~2008 | Millions of messages | Automated corporate mail of all kinds |
| Godai Group doppelganger study | 2011 | 120,000+ emails, 20 GB in 6 months | Passwords, network diagrams, trade secrets, litigation files |
| Mali .ml / .mil typo | 2013–2023 | ~117,000 messages in 6 months of 2023 | Military medical data, base maps, staff lists, itineraries |
| noreply.net and related domains | 2020–2026 | 437,000+ messages, 28,365 attachments | Injury reports, account credentials, customer PII |
Same root cause every time. Four different decades of headlines, one unfixed assumption.
Why do companies keep making this mistake?
Because “noreply” became a design pattern that assumes silence on the other end, and DNS does not care about your assumptions. The leaks come from a handful of recurring sources, and Solovewicz’s own catch-all logs confirm each one.
Deleted-user stubs. When an account is removed, some systems overwrite the email field with a value like deleteduser@noreply.net instead of ending the mail flow. The notifications keep firing at the new address forever.
Placeholder values in production. Developers type an address that “looks fake” into test data, default configs or required form fields. Test data migrates to production. The fake-looking domain turns out to be real, registered and listening.
Reply-to misconfiguration. Customers reply to a noreply address, and if the reply-to points at a domain the company does not own, the customer’s response — often containing account numbers or personal details — lands in a stranger’s inbox.
Relay probes. Mail servers send RCPT TO verification probes to these domains, quietly confirming to an outside party which internal mailboxes exist. That is reconnaissance data, delivered free of charge.
Notice what is absent from that list: attackers. Every one of these is a self-inflicted configuration decision. Which raises the obvious question — if the industry has known about this since 2008, why is there no standard fix? There is. It is older than most of the systems leaking the data.
The fix has existed since June 1999
RFC 2606, published as an internet Best Current Practice in June 1999, reserved four top-level domains — .test, .example, .invalid and .localhost — plus the second-level names example.com, example.net and example.org. These names can never be registered by anyone. RFC 6761 later formalised exactly how software must treat them.
The one built for this exact job is .invalid. It has no registry, no owner, and can never resolve. An address like deleted-user@system.invalid is guaranteed to go nowhere, permanently, at zero cost.
One caution the researchers themselves flag: example.com is not a substitute for .invalid in production systems. It has live DNS, and some senders will still attempt delivery there. It exists for documentation and screenshots, not for values your mailer reads at runtime.
For domains you own that should never receive mail, there is a standard for that too. RFC 7505 defines the null MX record — a single MX entry of 0 . — that tells the world a domain accepts no email, so sending servers fail fast instead of retrying or falling back. Pair it with a restrictive SPF record (v=spf1 -all) and a DMARC reject policy on parked domains, the configuration long recommended by the M3AAWG anti-abuse working group for domains that send and receive nothing.
The internet reserved unregisterable placeholder domains in RFC 2606 in June 1999. Every email leaking to a registered lookalike domain in 2026 represents 27 years of available fix that a configuration simply never adopted.
A 30-minute audit beats a breach notification
You do not need a new product to close this hole. You need your outbound mail logs and a short list of questions. Here is the audit we recommend running, in order:
- Pull 90 days of outbound mail logs. Export recipient domains from your mail gateway, Microsoft 365 or Google Workspace logs. Deduplicate to a list of unique destination domains.
- Sort by what you do not control. Flag every domain your organization does not own and has not verified as a real counterparty. Pay special attention to anything that looks like a placeholder:
noreply,donotreply,deleteduser,test,example,fake,none, orinvalidspelled as a.com. - Grep your systems for hardcoded addresses. Search codebases, CRM exports, ERP vendor records and provisioning scripts for email fields containing domains you do not own. This is where deleted-user stubs and test data hide.
- Replace placeholders with
.invalid. Any address that exists only to fill a required field should end in.invalid. It cannot be registered, so it cannot leak. - Fix your reply-to headers. Every automated sender should have a reply-to on a domain you own, ideally a monitored mailbox. If a customer replies to your password reset email, that reply is sensitive by definition.
- Lock down your parked domains. For owned domains that send no mail: null MX, SPF
-all, DMARC reject. Three DNS records per domain, minutes of work. - Consider defensive registrations. The Godai research showed hostile parties registering corporate lookalikes as far back as 2011. If a one-character typo of your domain is available for $15, decide whether you would rather own it or find out who does.
In client network and email assessments, the outbound log review in steps 1 and 2 is consistently the fastest finding-per-minute exercise we run. Most organizations have never once listed where their automated mail actually goes, because outbound email is treated as fire-and-forget. The results tend to end the meeting early.
Frequently asked questions
Is sending mail to a noreply address illegal or a compliance violation?
Sending itself is not illegal, but the contents can trigger obligations. Misdirected messages in these cases included medical data and identity documents — the kind of records covered by HIPAA, state privacy laws and breach notification statutes once they reach an unauthorized recipient.
Why can’t we just use example.com for placeholder addresses?
Because example.com has live DNS and some mail systems will still attempt delivery to it. RFC 2606 reserved it for documentation. The .invalid TLD is the one guaranteed never to resolve, which makes it the correct value for production placeholder addresses.
How likely is it that our organization is affected?
The 2011 Godai study found 30 percent of the Fortune 500 exposed to lookalike-domain interception, and Solovewicz’s domains have received mail from 6,200 distinct root domains. If your systems send automated email and nobody has audited the destinations, assume yes until the logs say otherwise.
Do the researchers holding these domains report what they receive?
Solovewicz says he alerts affected organizations and pushes them to fix their configurations rather than naming them publicly. The Godai Group deleted all data collected during its study. But that is goodwill, not a guarantee — the Mali case shows what happens when a listening domain changes hands to a less friendly owner.
The bottom line
Every incident in this article shares one trait: no attacker was required. Companies mailed their own secrets to strangers because nobody checked where the mail went. The standards that prevent it — RFC 2606 from 1999, RFC 6761 from 2013 and RFC 7505 from 2015 — predate most of the systems doing the leaking.
Run the 90-day outbound log audit this month. Replace placeholder addresses with .invalid. Put null MX, SPF and DMARC records on every parked domain you own. Total cost: an afternoon.
If you would rather have a second set of eyes on it, ADAM Pulse (USA Telecom Consulting LLC) performs outbound email and DNS exposure assessments as part of our network security reviews. Contact us to schedule one: support@adampulse.us or (888) 989-4872.
What does AI data governance actually require in 2026? · Does Zoom use your meetings to train AI?
References
- WIRED, “Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All” (August 2026)
- WIRED, “Doppelganger Domains” and The Register (September 2011)
- Godai Group, “Doppelganger Domains” whitepaper (2011)
- Financial Times via The Hill and CNN on the Mali
.mlleak (July 2023) - IETF RFC 2606, Reserved Top Level DNS Names (June 1999)
- IETF RFC 6761, Special-Use Domain Names (2013)
- IETF RFC 7505, A Null MX No Service Resource Record (2015)
- noreply.net catch-all statistics (2026)