Security researcher Cory Solovewicz has been flooded with more than 401,000 unwanted messages since December 2024—an average of roughly 700 emails every single day—according to a presentation delivered at the Defcon security conference. The avalanche isn't spam or marketing blasts. Instead, companies and organizations are mistakenly routing other people's confidential details and internal secrets straight to his inbox, Solovewicz told attendees. He's received injury reports from municipal governments, pizza order confirmations, school platform account setup messages, repair service requests, and login credentials for testing platforms—all because he owns the domains noreply.us and noreply.net.

The noreply.net domain alone has attracted 400,000 messages in the year and a half since Solovewicz bought it in 2024, with 28,365 of those containing attachments. His older domain, noreply.us, purchased in 2020, has logged 37,255 emails over 2,345 days. In the month leading up to his conference talk, both domains combined pulled in more than 11,000 messages. The emails originated from over 14,000 distinct sender addresses spanning 6,200 root domains, all automated by company systems rather than written by individuals. Meanwhile, fellow security researcher Mike Sheward, who leads security at EV charging firm Xeal, spent around $15 earlier this year to acquire deleteduser.com and saw three different organizations send material to addresses on that domain within the first hour. Sheward has since witnessed thousands of misdirected emails from at least 100 separate organizations across multiple domains he now controls, including details of Viagra orders, vacation approval requests, hotel bookings with full names, and invitations to Zoom meetings from a UK government agency.

"I created an accidental honeypot," Solovewicz told WIRED, explaining he had no idea his personal email project would balloon into a large-scale warning operation. According to the researcher, companies appear to be sending messages to addresses like companyname@noreply.net under the assumption the emails go nowhere or can't be monitored, or they may be converting individual email addresses to placeholder-style domains when employees leave or accounts are deleted. Solovewicz said he's "relieved" he acquired the domains rather than criminal hackers or nation states who could exploit the data maliciously. "I just want companies and organizations to do the right thing and to be auditing their systems and fixing their stuff," he stated. Sheward wrote in an April Medium post that he's "being a good guardian of the internet dumpster—but if I had been a bad one, it's not hard to see how this information that is willingly thrown at my face could be misused."

The problem is entirely avoidable, the researchers say. Companies could instead use internal domains or the .invalid domain, which is guaranteed never to exist. The issue isn't new—nearly 20 years ago, journalist Brian Krebs reported that companies were sending millions of messages to @donotreply.com addresses—but it persists at scale. Solovewicz built a scanning tool to test whether other potential placeholder domains are set up to receive email and found that out of 7,136 domains examined, 328 had catch-all inboxes configured. "I'm not sure I can say how large of a problem this is, but my concern is that what I 'accidentally' found when I registered my domain is just the tip of the iceberg," he noted during his talk. Recognizing the goldmine this data would represent to hackers and extortionists, both Solovewicz and Sheward have independently purchased more than 30 domains in an effort to keep them out of malicious hands.

Both researchers have been notifying affected companies of their misconfigurations, though results have been mixed—some organizations quietly fixed the flaws, many haven't responded, and the sheer volume makes reaching everyone a challenge. "I'm at the point where this would now be a full-time job to handle every single one of these—that's part of my motivation to talk about this, it is my responsible disclosure," Solovewicz said, urging companies not to assume any domain is unmonitored. "You guys need to fix your systems and not do this and not leak your customer data and your employee data and your own internal data." The takeaway is blunt: organizations must audit their email configurations and stop treating placeholder domains as black holes, because someone is almost certainly watching. The accidental honeypot experiment underscores that even well-intentioned researchers can stumble into surveillance capabilities that would be devastating in the wrong hands, and enterprises that treat system hygiene as optional are gambling with customer trust at a moment when regulators and the public have little patience left for preventable breaches.