
Fifteen dollars is roughly what it costs to start reading email your company thinks nobody receives. Two security researchers who quietly bought placeholder domains — the ones enterprise systems fall back on when an address is retired or an alert needs a fake sender — have collected hundreds of thousands of misdirected corporate messages, and their own scanning suggests hundreds of similar domains are already sitting on live inboxes.
Cory Solovewicz, a security researcher and consultant, laid out the problem at the Defcon security conference this week. He registered noreply.us in 2020, intending to use it as a personal catch-all (an inbox that accepts mail sent to any address on a domain), then noticed that unrelated corporate systems were already mailing it. "I created an accidental honeypot," he told WIRED.
The volume since has been extraordinary. His noreply.net domain, bought in 2024, has taken close to 400,000 messages in about 18 months, 28,365 of them carrying attachments.
The mail arrives from more than 14,000 sending addresses across 6,200 root domains, all of it machine-generated: injury reports from a city government, service tickets, school platform signups, and, repeatedly, credentials for test environments.
Mike Sheward, head of security at EV charging company Xeal, ran the same experiment with deleteduser.com. Three organisations emailed it within the first hour. Since then, he has received leave-approval requests, hotel bookings with full guest names, Zoom invites from a UK government agency, and thousands of CCTV stills from an AI vendor monitoring worker safety at Middle East industrial sites — traffic from at least 100 organisations, several of them security vendors themselves.
Rather than deprovisioning an account, many systems simply rewrite the user's address to a placeholder domain the company does not own. Brian Krebs documented the same failure with donotreply.com nearly two decades ago.
The exposure is wider than two inboxes. Solovewicz probed 7,136 candidate placeholder domains and found 328 with catch-all inboxes already configured.
Fixing it is cheap: audit outbound mail for external placeholder domains, switch no-reply senders to a subdomain you control or to .invalid (reserved by RFC 2606 and guaranteed never to resolve), and make account deletion actually delete rather than rename.