redomainer

Data-driven insights for domain investors.

News

How Owning a Noreply Domain Exposes Thousands of Corporate Secrets

Ars Technica reports that security researcher Cory Solovewicz owns noreply.net and noreply.us — domains he purchased in 2024 and 2020, respectively — and has logged over 400,000 inbound messages at the addresses since December 2024. The mail is not spam.

Tobin Carmody·updated August 11, 2026

How Owning a Noreply Domain Exposes Thousands of Corporate Secrets

It is automated corporate traffic, misrouted by senders who treat noreply-style domains as a guarantee of non-delivery. For domain investors, the case file is a controlled experiment in what a parked catch-all actually captures.

The acquisition and the catch-all mechanics

Solovewicz bought noreply.us in 2020 with the stated intent of building a personal catch-all inbox. A catch-all accepts any address at the domain, regardless of whether the local-part exists. By 2024 he added noreply.net to the same configuration. He did not anticipate what would follow. Per his own audit, noreply.net received 401,796 messages between December 2024 and his Defcon presentation — a stated average of 699.99 per day. noreply.us, the longer-held asset, has logged 37,255 messages across 2,345 days. Solovewicz presented the dataset publicly at Defcon.

What the mail reveals

The bodies are not noise. Solovewicz reports receiving municipal injury reports, pizza order confirmations tied to specific customers, account-setup emails from a school platform, service orders for individuals scheduling repairs, and test platform credentials. Of the 401,796 messages on noreply.net, 28,365 carried attachments. The traffic originates from over 14,000 distinct "from" addresses across 6,200 root domains. The sender systems are automated, not human, and the messages contain data the senders clearly intended to reach internal mailrooms or test queues. Solovewicz states he is notifying affected organizations and not publicly naming them.

The pattern is not new. Brian Krebs documented analogous behavior around @donotreply.com two decades ago while at the Washington Post. RFC 6761 reserves the.invalid TLD specifically for addresses guaranteed not to exist; corporate developers continue to use noreply-style strings anyway, because the local-parts read as inert. They are not.

What this means at the auction block

Two readings matter here. First, on the buy side: short, branded-looking generic strings with no inherent SEO profile — noreply.net being the textbook case — can be acquired cheaply, parked under catch-all, and audited for inbound traffic as a side channel. The data Solovewicz extracted is sensitive enough that he presents it as a security disclosure; the asset itself was available at registrar cost. Second, on the risk side: any portfolio holding catch-all mail on a low-utility domain is receiving unsolicited third-party data, ranging from credentials to internal system reports. A registrant who does not adopt a notification-and-purge protocol inherits whatever flows in. Domain portfolios are increasingly treated as alternative investments sitting alongside private equity and venture capital allocations, and the same due-diligence rigor should apply to any domain lot on the auction block — specifically to whether the strings previously hosted mail flows and what those flows contained.

We do not have a price on either noreply domain. We have a verdict: a parked catch-all on a string like noreply.net is not a passive asset. It is a logging endpoint. Buyers should price the liability accordingly.