K12Smart Phish

Simulation domain policy

K12Smart operates a set of internet domains used solely to deliver authorized phishing simulations for K-12 school districts. This page explains what those domains are, how to confirm that a particular domain is one of ours, and how to reach us about it.

What the domains are for

K12Smart Phish lets a district run phishing simulations against its own staff: a realistic but harmless practice message, followed by a short training moment for anyone who clicks. The exercises are configured by the district's own administrators, sent only to recipients they select, and run only while the district is under contract with us.

A simulation only teaches anything if it looks like the real thing, so a practice message is sent from a domain that resembles a familiar sender. That resemblance is confined to the exercise itself. The root of every one of our domains serves a plain ownership notice naming us as the operator, so anyone who visits a domain directly — rather than through a simulation link sent to them — sees what it actually is.

What we never do

Confirming a specific domain

Any domain we operate can be checked in three independent ways:

We do not publish the full list of domains on this page. Publishing it would hand every recipient a lookup table for defeating their district's exercises, which would defeat the training itself. Confirmation of any individual domain is available on request, immediately, to reviewers, registrars, hosting providers and the security team of any district we work with.

Reporting a domain

If one of our domains is being used in a way this policy does not describe — or you believe a message from one reached someone it should not have — tell us and we will act on it. Reports go to report.abuse@k12smart.com; the abuse page lists what to include so we can trace a message to the exercise that produced it.

Who we are

OperatorLearning Technology Center (K12Smart)
ProductK12Smart Phish
Websitek12smart.com
Product consolephish.k12smart.com
Abuse & securityreport.abuse@k12smart.com
© 2026 K12Smart · Report abuse · security.txt