Simulation domain policy
K12Smart operates a set of internet domains used solely to deliver authorized phishing simulations for K-12 school districts. This page explains what those domains are, how to confirm that a particular domain is one of ours, and how to reach us about it.
What the domains are for
K12Smart Phish lets a district run phishing simulations against its own staff: a realistic but harmless practice message, followed by a short training moment for anyone who clicks. The exercises are configured by the district's own administrators, sent only to recipients they select, and run only while the district is under contract with us.
A simulation only teaches anything if it looks like the real thing, so a practice message is sent from a domain that resembles a familiar sender. That resemblance is confined to the exercise itself. The root of every one of our domains serves a plain ownership notice naming us as the operator, so anyone who visits a domain directly — rather than through a simulation link sent to them — sees what it actually is.
What we never do
- We never collect credentials. The practice sign-in pages carry no submittable form — fields have no name, forms have no action — and the platform records only that a button was pressed. No password or typed value reaches our servers, from any exercise, ever.
- We never serve downloads, executables, or software of any kind to visitors.
- We never send simulations to anyone outside a contracted district's own selected recipients, and never to the general public.
- We never use these domains to send commercial mail, host live services, or collect data from uninvited visitors.
Confirming a specific domain
Any domain we operate can be checked in three independent ways:
- Load the domain's root in a browser. It serves an ownership notice naming K12Smart, the product, and this policy.
- Fetch
https://<domain>/.well-known/security.txt. It carries our abuse contact and points back to this policy, with the domain itself as the canonical host. - Email report.abuse@k12smart.com with the domain name and we will confirm or deny it in writing.
We do not publish the full list of domains on this page. Publishing it would hand every recipient a lookup table for defeating their district's exercises, which would defeat the training itself. Confirmation of any individual domain is available on request, immediately, to reviewers, registrars, hosting providers and the security team of any district we work with.
Reporting a domain
If one of our domains is being used in a way this policy does not describe — or you believe a message from one reached someone it should not have — tell us and we will act on it. Reports go to report.abuse@k12smart.com; the abuse page lists what to include so we can trace a message to the exercise that produced it.
Who we are
| Operator | Learning Technology Center (K12Smart) |
|---|---|
| Product | K12Smart Phish |
| Website | k12smart.com |
| Product console | phish.k12smart.com |
| Abuse & security | report.abuse@k12smart.com |