HeadlinesBriefing favicon HeadlinesBriefing.com

Researchers Capture Spam from Corporate Email Domains

Ars Technica •
×

Solovewicz, who keeps his victims unnamed, admits he didn’t foresee the scale of the problem. He’s been flagging companies with misconfigurations and urging them to audit and fix their systems. The domain noreply.net—his largest—has received 400,000 messages in a year and a half, 28,365 of which contain attachments. The sibling domain noreply.us has gotten 37,255 messages over 2,345 days since 2020. In the month before his conference talk, the two domains together received more than 11,000 messages.

Nearly 14,000 “from” addresses and 6,200 root domains have fed into these inboxes, all automated by company systems. The issue isn’t new; almost 20 years ago, security journalist Brian Krebs warned that millions of emails were sent to @donotreply.com addresses. Companies can avoid this by using internal domains or the guaranteed‑non‑existent .invalid domain.

Solovewicz isn’t alone. Mike Sheward, head of security at the EV‑charging company Xeal, bought deleteduser.com for about $15. Within the first hour, three different organizations sent emails to it. Sheward has received everything from Viagra orders to UK government Zoom invitations, highlighting the data privacy risks when companies merely change addresses instead of deleting accounts.