// phish report

Forward the email.
We'll tell you if it's a threat.

Get a full threat analysis report in minutes — no inbox connection needed. Works with Gmail, Outlook, Yahoo, AOL, iCloud, or any email provider.

Get your scan address → See a sample report
Gmail
Outlook
Yahoo
AOL
iCloud
+ any email
You forward this →
Forward Message
To you@report.drakaro.com
Subj [Action Required] Unusual sign-in to your account
From Chase Bank
Date Today, 9:14 AM

We detected a sign-in to your Chase account from an unrecognized device.

If this wasn't you, verify your identity within 24 hours to avoid account suspension.

Verify My Account →

© 2026 JPMorgan Chase Bank, N.A. · 270 Park Ave, New York, NY 10017

You get this back ←
// threat analysis report PHISHING
email analyzed
[Action Required] Unusual sign-in to your account
Chase Bank  ·  Today, 9:14 AM
Threat level 94 / 100
analysis

This is a phishing email impersonating Chase Bank with a fake sign-in alert and a malicious verification link.

The "Verify My Account" button leads to a fake Chase login page hosted at a website created just 6 days ago. If you enter your credentials there, attackers gain instant access to your bank account and can reset other accounts tied to your email.

what we noticed
  • Link goes to chase-secureportal.com — not chase.com
  • Website was registered just 6 days ago
  • Sender cannot verify they are Chase Bank
  • Fake 24-hour deadline used to pressure action
Do not click the link. Chase Bank only sends emails from @chase.com. Go directly to chase.com if you need to check your account activity.

how it works

Three steps.
No inbox access required.

No OAuth, no ongoing permissions. Just a forwarding address and a report back in your inbox.

🔑
STEP 01

Sign up and get your address

Create an account in seconds. You'll get a personal scan address like you@report.drakaro.com — yours to keep.

📨
STEP 02

Forward the suspicious email

Got something that looks off? Forward it to your Drakaro address — from any email app, on any device, on any provider.

📋
STEP 03

Receive your threat report

Within minutes, a plain-English threat analysis lands in your inbox. Is it phishing? Malware? Totally clean? We'll tell you exactly.


threat coverage

What we check.

Every submission runs a full multi-layer analysis — not just a blocklist lookup.

🎣

Phishing & Lookalike Domains

Catches domains built to impersonate real brands — character swaps, punycode tricks, typosquatting, and homoglyph attacks.

🔗

Malicious Links

Every URL is followed, redirects resolved, and destinations checked against real-time threat intelligence databases.

📎

Malicious Attachments

PDFs, Office docs, ZIPs — scanned for malware, macros, executables, and hidden payloads before they ever reach you.

📷

QR Codes

QR codes embedded in emails or attachments are decoded and their destinations scanned like any other link.

🪪

Sender Identity

DMARC, SPF, and DKIM checks verify whether the sender is who they claim to be. Spoofed addresses get flagged.

🧠

AI Threat Analysis

AI reads the full email to catch manipulation tactics, urgency tricks, fake invoices, and impersonation that evade filters.


One plan.
No surprises.

Cancel anytime. The report goes to you — we don't store anything.

$1/mo
20 submissions per month
  • Full threat analysis on every forwarded email
  • Phishing, malware, lookalike domains, QR codes & attachments
  • AI-powered content analysis
  • Plain-English report delivered straight to your inbox
  • Works with any email provider — no exceptions
  • No inbox access required
Get started — $1/mo
faq

Questions.

Any email provider at all — Gmail, Outlook, Hotmail, Yahoo, AOL, iCloud, ProtonMail, corporate email, school email. If you can forward an email, you can use Drakaro Phish Report.
Each email you forward to your Drakaro address is one submission. You get 20 per month. Unused submissions don't roll over to the next month.
Usually within 60–90 seconds. Emails with many links or large attachments can occasionally take a few minutes.
No. Your email is analyzed and the report is sent straight back to you — that's yours to keep. We don't store anything on our end. No account history, no scan logs, nothing is retained after the report is delivered.
You'll get a report saying it's clean, with a summary of everything checked. Confirmation that nothing was hiding is still useful.
Never. You choose what to send. We only see the individual emails you forward to your scan address — nothing else in your inbox.