Did You Realize noreply.us and noreply.net Are Real Domains?
Not Everyone Does; Those Emails Do Go Through
We’ve all fed fake email addresses into websites that demand you give them one but don’t require you to verify it. Companies do the same, filling in the From: field on their automated emails with some variety of noreply in the email address. If the address provided to customers is inside of a domain you own, for example noreply@pcper.com, you and those you email are safe. However if you are depending on something like newsletter@oreply.com then you are in for a nasty surprise; that domain exists and your email will end up being delivered to somewhere you do not control.
The good news is that both the noreply.us and noreply.com domains are owned by an ethical security researcher who is not taking advantage of the information contained in the hundreds of thousands of emails that end up on his mail server. The contents of the emails his two noreply domains get would be a gold mine for a less principled owner as many of these emails are not simply a demand for someone to stop spamming them.
This is not new, indeed back in the ancient time when Brian Krebs worked for Washington Post he tried warning people about a similar address that was being used improperly. The .invalid domain is a real thing and guaranteed to be a proper disposal for unwanted email replies as it is not and never will be a valid domain.
After originally planning to use the noreply.us domain as a catch-all email—which receives mail sent to any @ address on that domain—to filter messages and enhance his privacy, the researcher quickly noticed that other systems were sending mail to @noreply.us addresses.
More Tech News From Around The Web
- AI-Powered Browser Just Generates Every Website From Scratch @ Slashdot
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs @ Bleeping Computer
- Microsoft Responds to Outcry After Quietly Installing Beta ‘Photos’ App on Enterprise Machines @ Slashdot
- Valve notifies Steam hardware customers of a data breach @ Bleeping Computer
- Framework Notifies ‘All Customers’ of a Data Breach Via Compromised Metabase BI Service @ Slashdot
- Real emails, hijacked payments: Two H1 2026 attack chains @ Bleeping Computer
- N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands @ The Register
- Unlimited Technology Systems breach impacts 3.8 million people @ Bleeping Computer
- Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway @ The Register
- AMD acquires AI chip startup Taalas to boost inference performance by etching models into silicon @ The Register
- Privacy Backlash Explodes Against Meta’s Smart Glasses @ Slashdot
- A 10M IOPS Kioxia GP1 SSD Shown Running at FMS 2026 @ ServeTheHome
- WisdPi WP-UT9 USB 10GbE Adapter @ ServeTheHome


