Two security researchers purchased cheap domain names including noreply.net and deleteduser.com, configured mail servers and began receiving thousands of emails from Fortune 500 companies, government agencies and startups. The emails contained password reset links, invoices, proprietary documents and other sensitive data sent by automated systems that never expected a reply.
How the Experiment Worked
The researchers, whose work has been framed as an investigation into why “Sensitive Info Goes Into No Reply Emails Constantly,” identified domains commonly used in outbound corporate mail that were no longer registered. They purchased noreply.net, deleteduser.com and several similar names, then set up mail servers to accept all messages sent to any address on those domains. Within days, the servers filled with internal communications, password resets, shipping confirmations and financial records from hundreds of organizations.
The effort, which one researcher described as a case of “This Guy Sees It All,” did not require hacking or phishing. The researchers simply allowed emails to arrive naturally because many companies had not configured DNS records such as SPF, DKIM or DMARC to reject messages from unapproved servers. Even companies with strict security postures sometimes failed to secure auxiliary domains used for legacy systems or automated notifications.
What Data Was Exposed
The captured emails fell into several categories, each representing a distinct privacy or security risk. The researchers cataloged examples ranging from mundane to alarming.
The researchers noted that many of these emails contained personally identifiable information subject to data protection regulations. The volume of traffic suggests the problem is widespread and persistent.
Why This Matters
The experiment exposes a blind spot in corporate email security that attackers could exploit with minimal effort. A malicious actor who registers a decommissioned domain could harvest reset links to hijack accounts, gather competitive intelligence or commit fraud. Companies face tangible legal and reputational risk if customer data leaks through an unmonitored email channel these same companies created.
Regulators and security frameworks have long recommended that organizations authenticate all outbound mail and retire domains properly. This demonstration proves that many have not followed that guidance. The practical consequences include increased risk of account takeovers, data breaches and compliance failures. Going forward, organizations must treat every domain in their email ecosystem as a critical asset and implement strict controls on automated message delivery.



