Researcher buys noreply.net, receives 3,000+ corporate secrets
A researcher buying noreply.net received thousands of sensitive internal emails from major companies, revealing a widespread security flaw where firms treat noreply addresses as secure. This practiceโฆ
A researcher bought the domain noreply.net and immediately started receiving sensitive internal messages from major companies. In the first 48 hours, he got emails labeled โconfidential,โ delivery confirmations for restricted shipments, and even a password reset link for an executiveโs corporate account. The inflow confirmed a long-suspected flaw: thousands of firms treat โnoreplyโ addresses as digital trash cans instead of secure inboxes.
Companies use noreply@ domains to cut down on inbound spam and noise, but the practice quietly creates a backdoor. Marketing, logistics, and HR systems often send order details, meeting invites, and system alerts to these addresses without encryption or authentication. The volume has risen as firms automate more workflows and rely on third-party tracking pixels that auto-fill sender fields. Security researchers have warned for years that noreply domains can become a single point of failure, but many CISOs still see them as low-risk.
During the first week, the researcher catalogued messages from at least 16 Fortune 500 firms across retail, banking, and tech. One email contained a CSV of employee home addresses labeled โDo Not Share.โ Another listed software license keys for an entire data center. A third warned of a phishing campaign already inside the companyโs VPN logs. Major providers like Microsoft and Google confirmed they allow noreply domains to receive mail on their platforms, and neither has a plan to block them outright.
The next step is unclear. The researcher has forwarded the evidence to the affected companies and to CISA, but so far only a handful have responded. Security experts expect a patchwork of settings changes rather than a universal fix. Meanwhile, the domain itself remains up, still collecting secrets. The stunt shows how a $12 domain can expose corporate blind spotsโand why โout of officeโ should never mean โout of sight.โ
Read Full Story at Ars Technica โ


