Security researchers have uncovered a surprising email security problem: companies are accidentally sending private information to internet domains that were never intended to receive it.
Researchers Cory Solovewicz and Mike Sheward discovered the issue after purchasing domains such as noreply.net, noreply.us and deleteduser.com.
Instead of receiving only spam, the researchers began getting automated emails containing information that could potentially expose customers, employees and businesses.
Thousands of Misrouted Emails
Solovewicz says his noreply.net domain received more than 400,000 emails during roughly a year and a half. Thousands of those messages reportedly included attachments.
The emails included different types of information, ranging from service requests and account notifications to test credentials and other business-related data.
Sheward experienced a similar problem after purchasing deleteduser.com for around $15. He reportedly began receiving emails from organizations within hours of setting up the domain.
Some messages contained personal information, meeting invitations, booking details and other internal communications.
How Does the Problem Happen?
The issue appears to come from poorly configured automated email systems.
Some organizations use addresses such as user@noreply.net or employee@deleteduser.com as placeholders. When an account is deleted or a person leaves an organization, the system may continue sending messages to the old address instead of properly removing or redirecting it.
If the domain is owned by someone else, those messages can end up in an unexpected inbox.
Security researchers warn that attackers could potentially take advantage of the same weakness to collect sensitive information.
Researchers Warn Companies to Fix the Problem
Both researchers say they have been contacting organizations when they discover misconfigured systems.
Solovewicz also tested thousands of other possible placeholder domains. He reported finding hundreds that appeared to accept incoming messages through catch-all email configurations.
The researchers are keeping the identities of affected organizations private while encouraging companies to audit their email systems and correct the configurations.
The discovery highlights a simple but often overlooked cybersecurity problem.
An email address that looks like it should be inactive or unmonitored may still belong to a real person or organization.
Companies should regularly review automated email workflows, remove outdated addresses and avoid using real internet domains as fake or placeholder addresses.
For systems that should never send real email, security experts can instead use reserved domains such as .invalid, which are specifically designed not to resolve to real services.
Read More on VitalStack
- Google Pixel Watch 5 Launches With Smarter Gemini AI and New Health Features
- OpenAI Report Shows AI Coding Agents Are Speeding Up Scientific Software Development
- Google AI Overviews Now Appear in Nearly Half of Search Results, Changing How People Search Online
- Snapchat Stops Rewarding Fully AI-Generated Spotlight Videos to Promote Original Creators
Enjoyed this article?
Subscribe for weekly deep-dives on AI and health — straight to your inbox.