Report abuse
Write to report.abuse@k12smart.com. It reaches our security team directly, and it is the fastest route for anything involving a domain we operate.
Did you get a suspicious email at work? Report it to your own IT or security team first — they can tell you immediately whether it was a training exercise they scheduled, and they can act on it if it wasn't.
What to include
Any of these lets us trace a message to the exercise that produced it:
- The domain name in question.
- The message's full headers, if you have them — this is the single most useful item.
- The recipient address and roughly when it arrived.
- A screenshot or the message body, if headers aren't available.
What happens next
- We identify which exercise and which district the message came from, and confirm back to you whether the domain is ours.
- If a message reached someone outside the district's own selected recipients, we tell the district and stop the exercise.
- If a domain of ours is being used in a way our simulation domain policy does not describe, we suspend it.
- Reviewers, registrars and hosting providers: we answer ownership and takedown questions in writing, and can supply the operating detail behind any single domain.
Security reports
Vulnerability reports go to the same address, and every domain we operate publishes a matching security.txt record. Please give us a reasonable window to fix an issue before disclosing it.