Today, we’re sharing a story—a story about a vision for education that goes beyond the classroom and into the digital systems that connect us all. Our team is building a coherent system for education, a unified and highly functional technology ecosystem that brings clarity and security to school communication.
We believe that the future of education depends on systems that are not only powerful but also trustworthy. We’ve all felt the frustration of a fragmented digital landscape, a chaotic mix of generic email addresses and disjointed platforms that make it hard to feel connected and secure. This is the problem our work aims to solve.
At the core of this project is a logical email system structure. We designed a framework for organizing communication that is a foundational component of a larger, integrated system. This isn’t a standalone concept; it works in tandem with our other initiatives to create a unified network. Our system includes separate, secure domains for parents, teachers, and students. This clear separation is a direct implementation of our architecture, ensuring communications remain distinct and secure.
To make this system truly effective, we’ve developed a common-sense naming convention. By creating a clear, consistent, and predictable naming structure, our system becomes instantly understandable to all users. A parent can immediately recognize a message from the teacher.email or a school announcement from the school.email without needing to decipher a complex address. This logical system structure and our rational naming convention work together to eliminate confusion and streamline communication.
Beyond organization, our system is built on a robust technical foundation. We’re using open-source protocols and a hybrid decentralized model to ensure the security and scalability required for a system with separate domains. This architecture is crucial for a secure and scalable network.
The result is a system that isn’t just about email organization. It’s a central hub that allows our other initiatives, from our hybrid decentralized communication model to our rational naming conventions, to function cohesively. This logical structure is also essential for integrating emerging technologies like AI. Our AI assistant can use the clear, domain-based system to categorize communication with greater accuracy, providing a contextually relevant response for every user.
Our work is creating a unified system that is secure, scalable, and intelligent, serving our entire educational community. We are excited to share our progress and continue building this coherent system for the future of education.
In today’s digital age, artificial intelligence (AI) is transforming education by providing personalized learning experiences, streamlining administrative tasks, and enhancing communication between students, parents, and teachers. However, one major challenge remains: fragmented and inconsistent student data. A universal email system, where students maintain a structured email address throughout their academic journey, is the key to unlocking AI’s full potential in education.
The Role of a Universal Email System in AI-Driven Education
Currently, students use a mix of personal, school-assigned, and third-party email addresses, making it difficult for AI systems to track and analyze learning progress across different platforms and grade levels.
A standardized email system, structured by school level (e.g., phonenumber@elementaryschool.email, phonenumber@middleschool.email, phonenumber@highschool.email), offers numerous advantages:
Seamless Data Tracking & Personalization AI thrives on data. A universal email system ensures that student interactions, coursework, and academic progress are consistently logged and analyzed across multiple years. This allows AI to tailor learning resources, recommend personalized study plans, and identify areas where students may need extra help.
Enhanced Parental Involvement With a structured system, parents can receive timely updates on their child’s progress, school announcements, and AI-generated insights on academic strengths and weaknesses. This fosters better communication and collaboration between educators and families.
Optimized Teacher Workflows AI-driven grading, feedback, and administrative processes become more efficient when tied to a single, organized email system. Teachers can track student participation, manage assignments, and provide data-driven recommendations without the confusion of multiple email identities.
Improved Security & Privacy A controlled, school-managed email system ensures student data is protected under strict privacy guidelines. Unlike personal emails that may expose students to phishing, spam, or cyber threats, a dedicated educational email system allows AI-powered cybersecurity measures to safeguard communications.
Better Transition Between Grade Levels Rather than creating new accounts every time a student moves up a grade or changes schools, a universal email system provides continuity. AI can use this uninterrupted data to build long-term learning profiles, enabling smarter recommendations for career pathways and college readiness.
AI-Enhanced Education Starts with Better Data
For AI to truly revolutionize education, it needs clean, structured, and continuous data. A universal email system acts as the foundation for this by providing a single, trackable identity for each student. When AI can reliably analyze years of learning patterns, schools can:
Predict and prevent academic struggles before they become critical
Personalize lesson plans to match individual student needs
Automate administrative tasks, freeing up educators to focus on teaching
Summary
A universal email system is more than just an organizational tool—it’s a game-changer for AI in education. By ensuring consistent data flow, improving security, and enhancing communication, this system empowers students, parents, and teachers with the insights needed to create a smarter, more effective learning environment.
The future of education is AI-driven, but AI can only be as good as the data it learns from. A universal email system is the essential infrastructure needed to build the next generation of intelligent, student-focused educational technology.
Written by the Department of TechnologyFiled under: Department of Technology, Education Technology
An Everyday Failure Hiding in Plain Sight
Picture a school office on a Tuesday morning. A message arrives that looks like it’s from the principal: early dismissal today, please have your child ready at noon. A dozen parents act on it before anyone notices the sender was never verified against anything — because there’s nothing to verify it against. No registry, no authentication, just an email address that looked plausible.
Or picture a different Tuesday: a threat is unfolding on campus at 9:14 a.m. By 9:17, parents are calling a school switchboard that’s already overwhelmed, conflicting information is spreading on social media, and cars are backing up on the street outside, slowing down the first responders trying to get in.
These are the kinds of scenarios the School Contact Initiative was built to prevent. And the tool it proposes is, on its face, almost boring: a standardized identity system for everyone in K–12 education — students, teachers, administrators, and parents alike. But boring is exactly the point. The most important infrastructure in modern life — the electrical grid, the highway system, the domain name system that makes the internet navigable — tends to be invisible until the moment it fails.
American education doesn’t have that kind of infrastructure for identity and communication. School Contact proposes to build it. And building it at national scale may be a job that calls for a new federal institution: a Department of Technology.
The Problem Isn’t a Shortage of Technology. It’s a Shortage of Coherence.
Schools are not under-digitized. If anything, they are over-digitized in a way that has become unmanageable. The average U.S. school district now accesses nearly 3,000 distinct edtech tools in a single school year — a figure that comes from Instructure’s LearnPlatform EdTech Top 40 Report, since no federal agency currently tracks this at all. That’s not a typo. It’s thousands of logins, thousands of data-sharing agreements, and thousands of potential points of failure, layered on top of a student information system, an email platform, a learning-management system, and whatever apps individual teachers have adopted on their own.
That sprawl has a name — “Shadow IT” — and it has consequences that show up directly in the security data:
82% of K–12 schools reported a cybersecurity incident between July 2023 and December 2024, according to the Center for Internet Security’s MS-ISAC 2025 K–12 Cybersecurity Report, produced under a cooperative agreement with DHS/CISA.
45% of those incidents were phishing and “quishing” (QR-code phishing) attacks — the exact category of impersonation the scenario above describes.
55% of publicly disclosed K–12 data breaches since 2016 trace back to a compromised vendor — not the district itself — according to K12 SIX, the tracker the U.S. GAO itself relies on because no federal agency independently collects this data.
The average recovery cost of a ransomware attack on a K–12 institution is $2.28 million, the highest of any sector Sophos surveys in its 2025 State of Ransomware in Education report — and the GAO has separately found that recovery time alone runs 2 to 9 months.
None of this means schools adopted too much technology. It means they adopted it without a shared foundation underneath it — a common, verifiable answer to a deceptively simple question: who, exactly, is this?
The Missing Layer Is Identity
Every one of the problems above traces back to the same root cause: American education has no unified way to verify who is on the other end of a message.
A teacher who switches districts gets an entirely new email address, and every parent and student who knew the old one has to relearn it. A student who moves from Portland to Chicago gets an entirely new account, and years of communication history and academic context are severed in the process. A parent trying to reach their child’s teacher might use email for one, an app for another, and a phone call for a third — with no consistent way to prove, cryptographically, that a message claiming to be from “the school” is actually from the school.
School Contact’s answer is a dual-domain identity architecture: every person gets a short, easy-to-say, voice-friendly address for everyday use, which routes behind the scenes to a longer, detailed administrative address used for authentication and compliance.
The framework proposes a national numbering plan, similar in spirit to a telephone area code system, in which the first digits of every identifier signal a person’s role:
Prefix
Role
111
Institutions and agencies (a district, school, or state/federal education agency)
222
Certificated instructional staff — teachers and principals share this code, distinguished by domain (@teachers.email vs. @principals.email)
333
Classified and operational staff, using subdomain delegation on the institutional domain (e.g., @lausd.schools.email)
444, 555, 777, 999
Students — four parallel number pools spanning K–12, together sized for roughly 80 million identities
—
Parents and guardians bring their own existing mobile number as the handle for an @parent.email identity, verified by a one-time SMS code at enrollment — nothing new to memorize, and no new number consumed from the national pool
A teacher’s everyday alias might look like 2220684592@teachers.email — spoken aloud as “two-two-two, zero-six-eight, four-five-nine-two, at teachers dot email.” That number is deliberately built to be parsed correctly by voice assistants and transcribed correctly by any device, in any classroom, every time. Behind it sits a longer administrative address — built from a two-digit federal state ID, digits drawn from the educator’s state-issued credential number, and role and location data — used for logging, authentication, and oversight. It’s never exposed in ordinary conversation, which shrinks the surface area available to phishing and impersonation attempts.
Students illustrate the model’s real payoff. Under the proposal, a student keeps the same 10-digit number for their entire K–12 career, while only the domain changes as they move between schools or tracks:
4448587392@elementaryschool.email
4448587392@middleschool.email
4448587392@highschool.email
Two additional domains handle track changes without touching the number: @college.email for students on a preparatory or magnet track, and @students.email for those on an alternative or nontraditional track. The person doesn’t change. The number doesn’t change. Only the institutional context around them updates — which is precisely how identity should work, and precisely how it currently doesn’t work in most districts.
Not Another App — a Layer Underneath All the Apps
It would be easy to mistake School Contact for one more platform competing for space among the thousands districts already juggle. That misunderstands the proposal entirely.
School Contact is not asking districts to abandon their student information systems, their learning-management platforms, or their preferred communication tools. It is proposing a common identity layer that those systems can plug into — the way countless independent websites and email providers all rely on the same underlying domain name system without anyone having to agree on a single browser or a single email client.
That distinction matters, because it points to why this is a policy problem and not merely a procurement decision. No single school district, and no single vendor, has the standing to make an identity format work at national scale. Interoperability requires an authority that can sit above the competition between vendors and establish the common ground they all build on — the same role the FCC plays in coordinating telephone numbering, or the same role early internet standards bodies played in making it possible for any computer to talk to any other computer.
Why a Persistent Identity Requires More Than a Number
Assigning everyone a number is the easy part. The harder — and more consequential — part is governing what that number is allowed to do.
A responsible framework has to draw sharp lines between identity, authentication, authorization, communication, and educational records, so that a public-facing address never becomes a backdoor into a student’s file. It has to answer specific, unglamorous questions before a single line of code matters:
What happens to a student’s identifier when they transfer schools, or when they turn 18?
What happens to a teacher’s identifier when they leave a district?
Who is allowed to resolve an identity into a real person, and under what circumstances?
What information is public, what is private, and who audits the difference?
The School Contact framework has a specific answer for the student lifecycle question, sometimes called the “Graduation Release Protocol”: when a student graduates or turns 18 — whichever comes first — their 10-digit number is retired and returned to the national pool for a future kindergartener. Their actual records — transcripts, portfolios, disciplinary history — remain securely archived under a separate, randomly generated backend identifier for exactly five years post-graduation, so universities and employers can still verify a transcript without the original identifier remaining active and exposed.
These are not implementation details to be worked out after the fact. They are the actual substance of the policy, and they are exactly the kind of question a governing body — not a single vendor — should be answering in public, with input from educators, privacy experts, and security professionals.
Built to Fit Existing Privacy Law, Not Around It
A national identity system for children invites an obvious and fair question: what about privacy? The proposal’s answer leans on the structure of two existing federal laws rather than asking Congress to invent new categories from scratch.
Under the Family Educational Rights and Privacy Act (FERPA), schools may share limited “directory information” — like a name or a school-issued email address — without individual parental consent, subject to an opt-out. The School Contact identifier is designed to qualify as directory information rather than as a protected education record, and the framework also leans on FERPA’s “school official” exception, which permits sharing identifiers with vendors only when those vendors operate under the school’s direct control. Social Security numbers are explicitly excluded from the system entirely, and raw personally identifiable information is never shared with third parties.
Under the Children’s Online Privacy Protection Act (COPPA), which governs data collected from children under 13, the proposal uses the alias itself as a privacy tool through what the framework calls front-end tokenization. Consider a 12-year-old logging into a school-approved math tutoring app. Under most current systems, she’d enter her real name, grade, and a personal email address — data the vendor could combine with information from dozens of other apps to build a commercial profile of a minor, with little meaningful family awareness. Under School Contact, she enters only her alias, 4448587392@middleschool.email. The app learns she’s an authenticated 7th grader in the district — and nothing more. Her real name, her location, her cross-platform activity, none of it reaches the vendor. Parents, meanwhile, can see a running log of exactly which services have accessed their child’s identifier, when, and why.
None of this substitutes for a full legal review — it isn’t legal advice, and the developers of the initiative are explicit about that. But it shows a proposal built with existing statutory guardrails in mind, rather than one that would need to dismantle them.
An Accessibility Layer, Not Just a Security One
It’s worth pulling out a piece of the proposal that tends to get lost under the cybersecurity headlines: School Contact is also designed as an accessibility framework, aligned with the Americans with Disabilities Act and WCAG 2.1/2.2 guidelines.
The voice-friendly alias isn’t just convenient — it’s structural. A student, teacher, or parent who is blind or has low vision can manage an entire email identity through spoken commands, processed by standard speech-to-text and text-to-speech tools, because the numeric format was built to eliminate ambiguity between how something is written and how it’s spoken — no confusion between the character “5” and the word “five,” the kind of mismatch that trips up voice interfaces today. Standardized signature formatting is also built to avoid the image-only signature blocks that defeat screen readers. In a system this size, that’s not a minor feature. It’s the difference between an identity layer that works for everyone and one that quietly excludes the people who’d benefit most from it.
Where AI Changes the Stakes
Everything above would matter even without artificial intelligence in the picture. AI is what makes it urgent.
Imagine a parent asking a voice assistant, “Ask my child’s teacher whether tomorrow’s field trip is still happening.” For an AI system to act on that request safely — rather than guessing, or worse, impersonating a person — it needs a reliable answer to a chain of questions: Who is this parent? Which student are they actually authorized to represent? Which teacher is currently responsible for that student, and are they still active in that role? Which channel is the legitimate one to use? What information is this AI actually permitted to disclose?
Today, there is no infrastructure that can answer those questions with confidence. An AI agent operating in that vacuum either fails to act or, worse, fills the gaps with assumptions — exactly the kind of ambiguity that creates security and privacy risk. A standardized, authenticated identity and authorization layer is what lets an AI system operate within a framework of accountability rather than around one. That’s the practical meaning behind describing School Contact as AI-ready: not that AI should be everywhere in schools, but that when it does show up, it should be operating on solid ground.
What This Would Actually Cost
The initiative is upfront that its cost figures are illustrative estimates, not audited numbers, and they deserve the same scrutiny any policy proposal should get before becoming law. With that caveat: a 10,000-student district can reasonably spend tens of thousands of dollars a year on the indirect costs of platform sprawl alone — help-desk tickets for password resets, IT staff time keeping disconnected systems talking to each other — putting the estimated annual overhead for a mid-sized district in the $50,000–$200,000 range. The initiative benchmarks its own pricing against existing identity-management tools that charge as little as $1 per user per year, with a projected payback period within two years through reduced administrative overhead and consolidated licensing. Set against a single ransomware recovery averaging $2.28 million, the numbers are at least directionally worth taking seriously, even before anyone audits them.
What a Department of Technology Would Actually Do
None of this requires a new department to write software. It requires an institution with the standing to do the things individual districts and vendors structurally cannot do on their own:
Set standards. Work with educators, technologists, security professionals, and privacy experts to define common formats for identity, authentication, authorization, encryption, auditing, and account lifecycle events — the transfers, terminations, and graduations that current systems handle inconsistently or not at all.
Support interoperability, not mandates. Encourage vendors to build to shared standards so districts aren’t forced to reinvent identity infrastructure every time they adopt a new tool — the same logic that lets any email provider talk to any other.
Fund and evaluate pilots before scaling. The initiative’s own roadmap lays out three phases aligned with the federal government’s 2024 National Educational Technology Plan: six months of stakeholder alignment and needs analysis, a 6-to-18-month window for pilot programs in a deliberately varied set of districts alongside the formal FCC petition process, and national scaling from month 18 onward, backed by federal and state funding. Anchoring to a plan the government has already adopted — rather than starting from a blank page — is itself part of the case for taking this seriously.
Protect privacy as a design constraint, not an afterthought. Establish national principles around data minimization, purpose limitation, and accountability, so the system collects only what it needs to function — never more just because collection has become technically easy.
Reserve the numbering space. A national numbering plan of this kind would need formal coordination with the FCC and the North American Numbering Plan Administrator: a public-interest demonstration, proof that the system would be run by a neutral, non-discriminatory administrator, and coordination with state commissions, since the FCC often delegates portions of numbering jurisdiction to states for local implementation. That’s precisely the kind of cross-agency, cross-level coordination a dedicated technology department is positioned to lead.
Who Decides What, at What Level
A Department of Technology does not mean every decision gets made in Washington. The most workable version of this framework divides responsibility the way effective infrastructure programs usually do:
The federal government sets national standards for interoperability, cybersecurity, accessibility, and privacy, and coordinates the numbering plan with the FCC.
States translate those standards into education-specific requirements and coordinate adoption across districts.
Counties and local governments decide how those standards get implemented in their own communities.
Schools and educators stay focused on the educational mission the whole system exists to support.
National standards. Local implementation. Professional judgment left where it belongs — with the people closest to students.
Start With Evidence, Not Mandates
The internet did not succeed because a central authority dictated which applications people had to use. It succeeded because independent systems agreed to speak a common language, which let innovation happen everywhere above that shared layer. School Contact is proposed in the same spirit: start with research and technical specifications, engage the people who would actually use the system, run real pilots, and let the results — not the pitch — determine what scales. If a piece of it doesn’t work, change it.
This K–12 proposal doesn’t stand alone, either. A companion framework, College Contact, applies the same underlying diagnosis — that fragmented, unverified identity is a security and privacy liability — to higher education. It’s a deliberately separate system, not a continuation of the same identifier: a K–12 student’s number is retired at graduation under the Graduation Release Protocol, and College Contact is built around the different legal and structural realities of postsecondary life, where FERPA rights transfer from parent to student at 18 and a single person can hold multiple concurrent, institution-verified affiliations — an adjunct at one school while enrolled at another, for instance — rather than the single sequential affiliation a K–12 student has. Two purpose-built systems, not one identity carried through both, but both aimed at the same underlying problem: nobody can currently verify who’s actually on the other end of a message.
A Framework Worth Taking Seriously — With Eyes Open
It’s worth being direct about what this is and isn’t. School Contact, as described on its own site, is a community-driven policy proposal — a white paper and a set of draft model legislation, not enacted law, not the official position of any government agency, and not a finished product. The specific figures cited throughout are presented by the initiative as illustrative estimates, not audited numbers, and deserve the same scrutiny any policy proposal should get before it becomes law. That kind of transparency about what’s proven and what’s projected is itself a good sign for a proposal asking to be taken seriously as infrastructure.
But the underlying diagnosis is hard to dismiss: American schools are drowning in disconnected technology, identity fraud and impersonation are not hypothetical risks, and the arrival of AI agents that act on people’s behalf makes the absence of verified identity a problem that will only get more urgent, not less.
The question the country now faces isn’t whether schools need better technology. It’s whether anyone has the standing to build the foundation that technology depends on — before a thousand more disconnected products get built on a foundation that was never there. A Department of Technology, with the authority to set standards, fund honest pilots, and coordinate across every level of government, is one serious answer to that question.
Learn more about the School Contact Initiative at school.contact, including its full FAQ and interactive domain library — and about its higher-education counterpart at college.contact.