No Reply, Not Your Domain? Yes, Problem


As reported by Ars Technica, security researcher Cory Solovewicz owns the domains noreply.net and noreply.us. Every day, he sees nearly 700 inbound email attempts to addresses on those domains. That is a massive amount of misdirected mail, and it's leaking personally identifiable information (PII) like a sieve.

If you are sending mail using noreply.net (or any other domain you don't own), you are ensuring that bounces, spam rejections, out-of-office auto-replies, and real messages from actual humans are going to a complete stranger.

Never send email using a domain you do not own or have explicit permission to use. Doing so fails modern email authentication (SPF, DKIM, DMARC) checks, fails to comply with mailbox provider sender requirements, and guarantees your operational email traffic, and sensitive customer responses end up in unexpected places.

It's happening in my inbox, too

This issue isn't limited to noreply.net. A huge chunk of this misdirected volume comes from people typing fake or mistyped email addresses into sign-up forms that companies never bother to validate. From an email deliverability perspective, these are spamtrap hits, and this kind of poor list hygiene is exactly what gets senders blocked by Spamhaus and causes deliverability and reputation problems via multiple measures.

I recently divested myself of most of my 100+ spamtrap domains. (Don't worry, I didn't abandon them; I transferred management to an industry colleague who continues to utilize the traffic to help fight spam). But I kept a few domains, including one similar to Cory's. That one, in particular, is a recognizable domain that people routinely type into web forms.

On that single domain alone, I receive 600+ email attempts every single day, mostly from major brands you'd recognize. If a bad actor controlled that domain, they could easily "reset password" their way into taking over user accounts across dozens of popular platforms. Access reward points. Make purchases with stored credit card information. Hijack social media accounts.

It's sneaky, dangerous, and various evil people are almost certainly exploiting it already.

It's everyone's fault!

This problems here are caused by multiple bad choices: bad sender habits, reckless users, and a lack of proper email confirmation by companies. No matter who you are and where you are in the world of email, whether just a regular user, an email marketer, or managing a sending platform, everybody involved really needs to think about how they can do better to reduce these threats.
  • For users: Stop putting garbage or fake domains into forms. When you type in a fake email address to bypass a gate, you aren't being clever—you are potentially handing account control and your personal data over to an unknown third party who owns that domain.
  • For email senders: Only send mail from domains you own or control. Using a domain you don't have permission to use not only guarantees email authentication failures (thinking of SPF, DKIM and DMARC), but routes bounces and unknown volumes of personal information to third parties, along with causing damage to your sender reputation.
  • For companies: Verify email addresses before creating accounts or sending mail. If you don't require confirmed opt-in/double opt-in (COI/COI) before delivering sensitive emails, you are complicit in leaking customer PII and creating account takeover risks. Protect your users by verifying a user's access to a given email address first.
  • For email marketing automation platforms: Make it easy for your clients to confirm email addresses at the point of registration. Educate your clients on how to do this and why it matters, and how it will trickle down to protect their own customers against unauthorized account and data access.
I'm very happy to see this type of problem get attention elsewhere. It is important to remind people that spamtrap problems aren't just a deliverability and reputation problem; data privacy and data protection matter here, too.

Read the full story on Ars Technica: A researcher bought noreply.net. Companies started sending him secrets.
Post a Comment

Comments