Get a full threat analysis report in minutes — no inbox connection needed. Works with Gmail, Outlook, Yahoo, AOL, iCloud, or any email provider.
We detected a sign-in to your Chase account from an unrecognized device.
If this wasn't you, verify your identity within 24 hours to avoid account suspension.
© 2026 JPMorgan Chase Bank, N.A. · 270 Park Ave, New York, NY 10017
This is a phishing email impersonating Chase Bank with a fake sign-in alert and a malicious verification link.
The "Verify My Account" button leads to a fake Chase login page hosted at a website created just 6 days ago. If you enter your credentials there, attackers gain instant access to your bank account and can reset other accounts tied to your email.
No OAuth, no ongoing permissions. Just a forwarding address and a report back in your inbox.
Create an account in seconds. You'll get a personal scan address like you@report.drakaro.com — yours to keep.
Got something that looks off? Forward it to your Drakaro address — from any email app, on any device, on any provider.
Within minutes, a plain-English threat analysis lands in your inbox. Is it phishing? Malware? Totally clean? We'll tell you exactly.
Every submission runs a full multi-layer analysis — not just a blocklist lookup.
Catches domains built to impersonate real brands — character swaps, punycode tricks, typosquatting, and homoglyph attacks.
Every URL is followed, redirects resolved, and destinations checked against real-time threat intelligence databases.
PDFs, Office docs, ZIPs — scanned for malware, macros, executables, and hidden payloads before they ever reach you.
QR codes embedded in emails or attachments are decoded and their destinations scanned like any other link.
DMARC, SPF, and DKIM checks verify whether the sender is who they claim to be. Spoofed addresses get flagged.
AI reads the full email to catch manipulation tactics, urgency tricks, fake invoices, and impersonation that evade filters.
Cancel anytime. The report goes to you — we don't store anything.