
photo credit: [ Henning ]
This was brought to my attention by InternetDucTape. An interesting read actually.
So what is it, well, the domain name donotreply.com does actually exists. And it has a catchall email adress installed. Therefore any replies which you mistakenly send to this adress will get delivered. Your information is out there at that time.
The owner of the domain name has started posting some of the messages he receives online. And what can we see? That there are quite a lot of companies out there that rely on security who use this domain (i’m thinking banks, military organisations). And every time they use it, and someone replies, a message is send to donotreply.com
Why does donotreply.com put them online:
Why post them?
Because companies pay lip-service to security and privacy. Most of the companies listed here are giant corporations who should know better, who should have better policies in place. Some even offer services to you for if your credit cards or identity is stolen, yet they aren’t proactive about stopping that from happening.
The problem is, companies don’t always hire the right person for system administration jobs. Look at the horror stories over at thedailywtf. The position of system administrator is often left to hiring someone’s family member who is “good with computers”. It is a job that demands technical excellence, a system admin is not the janitor of the future, stop treating the position like it is. It is a hard job that needs smart people.And remember, if they are willing to be this careless with your information, where else are they careless? This is a minor, almost silly thing, what happens when it comes to things that are hard? That are expensive? I don’t trust them, do you?
For some more interesting reasons and discussions, check out the donotreply.com website
Examples:
Merril Lynch
Merril Lynch decided this was a good address to send mail from – Registration_and_Licensing_Services@… yeah you guessed it, not ml.com but donotreply.com.
So what fun do we find in the ML mail?
Roger D______
SUN LIFE / MFS Termination of Appointment in __________ has been terminated effective immediately due to one of the following reasons:
-Lack of business with this carrier
-State Insurance license has been terminated
-Per your requestYou will not be able to conduct any insurance business in NORTH DAKOTA for SUN LIFE / MFS until your appointment is reinstated.
Christopher ____ is pissed. He replied to the donotreply address with this angry little note from his blackberry.
Do not understand why terminated just got appointed. Please respond, I was told I needed to be appointed with them to hold Annuities that are in transfer. Please explain!
Capital One
This is one of the scarier ones. This is an identity theft nightmare. Seems when you make a certain kind of payment to your capital one account, the payment is sent from Capital One Payment . Can you see the problem here?
They don’t even bother to tell people not to respond to these emails, so I have customers sending complete emails like this one.
I have been waiting some time by now,
Can you e mail me the whole statement, the payments I did and closing the account because I think I lost
more money than interest, so I need to know where did I lost, you or Dr. ______.
ThanksS____ F______
—–Original Message—–
From: Capital One Payment [mailto:donotreply@donotreply.com]
Sent: Friday, September 14, 2007 8:32 PM
To: F_____, S______
Subject: Payment Confirmation9/14/2007
Dear S_____ F_____,Thank you for your recent payment to Capital One. This email is to confirm your authorization on 9/14/2007 12:01:39 PM for an electronic debit of your checking account in the amount of ____.___.
This payment will be effective on 9/14/2007 or shortly thereafter. If your financial institution is unable to process the electronic debit, Capital One is authorized to submit a paper draft for this transaction amount. In the event the debit to your account is returned unpaid, an additional return item will be debited from your bank account.
If you have any questions, or if this confirmation does not accurately reflect your payment, please contact us immediately at 800-926-1000.
Popularity: 8%
1 Trackback
[...] Why you should not use donotreply.com as your return adress [...]