Cory Solovewicz receives a deluge of unwanted emails, not spam but private company data. Since 2024, he’s received over 401,796 messages, including injury reports and test credentials.
He owns noreply.us and noreply.net, domains that companies misconfigure to send sensitive information instead of having it land in the trash. Solovewicz has alerted over 100 organizations about their mistakes, hoping they’ll fix them.
The issue isn’t new; almost two decades ago, Brian Krebs faced a similar situation. Yet, companies still send millions of emails to placeholder domains like @donotreply.com and @deleteduser.com.
Misconfiguration is avoidable by using internal or invalid domains, but the problem persists. Mike Sheward, head of security at Xeal, also bought several domains to protect data from malicious use.
Solovewicz’s work, presented at Defcon, involves scanning for catch-all inboxes and hopes that more organizations will learn from their mistakes before it's too late.







