Two security researchers purchased cheap domain names including noreply.net and deleteduser.com, configured mail servers and began receiving thousands of emails from Fortune 500 companies, government agencies and startups. The emails contained password reset links, invoices, proprietary documents and other sensitive data sent by automated systems that never expected a reply.

What You Need to Know

Companies routinely send automated emails from unmonitored addresses such as noreply@company.com. If the domain used in those addresses lapses or is never registered, anyone can register it and capture all traffic. Researchers demonstrated this by buying expired or unregistered domains that appear in corporate mailing lists. The problem affects companies of all sizes and points to a systemic failure in email security configuration. Organizations must ensure all sender domains are actively monitored and protected.

How the Experiment Worked

The researchers, whose work has been framed as an investigation into why “Sensitive Info Goes Into No Reply Emails Constantly,” identified domains commonly used in outbound corporate mail that were no longer registered. They purchased noreply.net, deleteduser.com and several similar names, then set up mail servers to accept all messages sent to any address on those domains. Within days, the servers filled with internal communications, password resets, shipping confirmations and financial records from hundreds of organizations.

The effort, which one researcher described as a case of “This Guy Sees It All,” did not require hacking or phishing. The researchers simply allowed emails to arrive naturally because many companies had not configured DNS records such as SPF, DKIM or DMARC to reject messages from unapproved servers. Even companies with strict security postures sometimes failed to secure auxiliary domains used for legacy systems or automated notifications.

What Data Was Exposed

The captured emails fell into several categories, each representing a distinct privacy or security risk. The researchers cataloged examples ranging from mundane to alarming.

  • Account credentials: Password reset links and temporary login tokens sent to email addresses that no one monitors.
  • Financial data: Invoices, payment confirmations and billing records that disclosed client names and transaction amounts.
  • Internal documents: Contracts, employee lists and project files mailed from automated workflows.

The researchers noted that many of these emails contained personally identifiable information subject to data protection regulations. The volume of traffic suggests the problem is widespread and persistent.

Why This Matters

The experiment exposes a blind spot in corporate email security that attackers could exploit with minimal effort. A malicious actor who registers a decommissioned domain could harvest reset links to hijack accounts, gather competitive intelligence or commit fraud. Companies face tangible legal and reputational risk if customer data leaks through an unmonitored email channel these same companies created.

Regulators and security frameworks have long recommended that organizations authenticate all outbound mail and retire domains properly. This demonstration proves that many have not followed that guidance. The practical consequences include increased risk of account takeovers, data breaches and compliance failures. Going forward, organizations must treat every domain in their email ecosystem as a critical asset and implement strict controls on automated message delivery.