Did you get an email from us?
You were right to check. Here is how to tell whether the message you received really came from us — and what to do if it did not.
We write from one address, and only this one: [email protected]
Four checks
A genuine message from us passes all four. If it fails even one, it is not from us — treat it as phishing and delete it.
-
Check the sender
It must come from [email protected]
Read the address character by character — not the display name, which anyone can fake. Any link in the message must begin with https://watchtower.team/ and nothing else. A different sender, or a link to any other site, means the message is not ours.
-
Verify independently
Ask us in a new email — never reply to the message
Open a blank email to [email protected], typing the address yourself. Copy in the reference code from the message you received — a short code near the top of the email that looks like WT-2026-4F3A. We will tell you within a day whether that message was ours. If it was not, we will say so plainly.
-
Keep control
We never ask you for any of these:
- A password
- A one-time code or two-factor code
- Remote access to a computer
- To install, download, or run anything
- A payment, of any kind
If a message claiming to be from us asks for even one of these, it is not from us.
-
Private by default
We tell you and nobody else — there is no deadline and no fee
We write to the affected organization directly, and we do not publish what we found. Nobody is pressuring you. What you do about it, and how fast, is entirely your call. A real message from us will never threaten to release anything.
Who we are
Watchtower is a small independent security research team. We are not a company, we are not selling anything, and our email is not a sales pitch.
We find security risks in data that is already public — web archives and other lawfully available sources. When something we find looks like it belongs to your organization, such as a password or key that was published by accident, we write to you privately and tell you what we saw and where we saw it. Then we are done. We do not publish it, sell it, or use it.
Still not sure? Ask us.
Write to us from scratch — a new message, not a reply. Include the reference code from the email you received and we will confirm whether it came from us.
[email protected]The same address is published in our watchtower.team/.well-known/security.txt, which is a second, independent way to confirm it.