Misconfigured 'No-Reply' Domains Are Leaking Company Data
08 Aug 2026
A $15 domain, hundreds of thousands of leaked emails
Two security researchers have shown just how easily companies can accidentally leak sensitive data through a common blind spot: no-reply and catch-all email domains.
Researcher Solovewicz purchased the domain noreply.us in 2020 and noreply.net in 2024, expecting to receive occasional stray traffic. Instead, one domain has accumulated 401,796 messages since December 2024 — an average of nearly 700 emails per day. Over roughly a year and a half, noreply.net alone collected about 400,000 messages, including 28,365 with attachments. The older domain, noreply.us, pulled in 37,255 messages over 2,345 days. In the month before Solovewicz presented these findings at the Defcon security conference, the combined domains received more than 11,000 messages from over 14,000 distinct sender addresses across 6,200 root domains.
Separately, Mike Sheward, head of security at EV charging company Xeal, spent about $15 to buy deleteduser.com. Within the first hour of ownership, three different organizations had already emailed content to that address. Sheward says he has since observed thousands of unintended emails from at least 100 different organizations across the domains he owns. Together, Solovewicz and Sheward have purchased more than 30 domains — largely, they say, to keep them out of the hands of malicious actors who could exploit the same misconfigurations.
Why this keeps happening
The root problem is domain misconfiguration. Some organizations use generic addresses like "no-reply" without registering or securing every plausible variant, while others operate catch-all inboxes that accept mail sent to any address at a domain — including typos or lookalike domains registered by someone else entirely. Solovewicz scanned 7,136 domains and found 328 with catch-all inboxes configured, a setup that can inadvertently funnel misdirected mail — including sensitive company and personal data — straight to unrelated third parties.
This isn't a new phenomenon. The report notes that nearly 20 years ago, Brian Krebs, then reporting for the Washington Post, wrote about companies sending millions of messages to @donotreply.com addresses. The persistence of the issue over two decades suggests it's less an isolated incident and more a systemic industry oversight.
What's missing from the picture
The researchers have not named the specific companies that mistakenly sent sensitive data, and it's unclear how organizations typically discover — or fail to discover — that their automated systems are leaking information this way. There's also no confirmation yet that any of the captured data has been exploited by malicious actors, and the exact methodology used to scan thousands of domains for catch-all configurations hasn't been detailed. It remains unclear whether large enterprises or smaller companies are more prone to this mistake.
Why founders should care
- It's plausible that a meaningful share of companies — including early-stage startups — have automated systems (password resets, notifications, transactional emails) routing through unmonitored or misconfigured domains, creating an invisible data-leak surface.
- Given that a lookalike domain can be acquired for as little as $15, the barrier to exploiting this kind of misconfiguration is low, meaning founders likely can't assume obscurity protects them.
- Because catch-all inboxes and no-reply setups are typically configured once and rarely audited, this risk may be more likely to go unnoticed in smaller teams without dedicated security review.
- The 20-year persistence of this pattern suggests that fixing it likely requires deliberate, recurring audits rather than a one-time configuration check — a process many resource-constrained startups may not currently have in place.
- This gap points to a possible market opportunity: tools or services that automatically detect misconfigured no-reply and catch-all domains could see rising demand as awareness of this risk spreads following public research like Solovewicz's Defcon talk.
The bottom line
The research suggests that email infrastructure — often treated as a "set it and forget it" utility — can become a quiet but significant data-leakage channel. For founders, the takeaway is straightforward: auditing domain configurations, no-reply addresses, and catch-all settings may be a low-cost, high-value security step worth prioritizing before an attacker (or a curious researcher) does it first.