FREE SUBMISSIONS + PRO APIS

Got a suspicious email? We'll handle it.

Forward phishing emails, scam messages, or suspicious attachments to us. ThreatDrop Free keeps suspicious-email forwarding open to everyone. ThreatDrop Pro adds customer APIs, webhook notifications, and detailed observed-evidence reports. Enterprise delivery is a contact-led scoped pilot discussion.

submit@blackdome.ai

Just forward the email. ThreatDrop Free needs no signup, and paid tiers unlock dashboard access for your own submissions.

How It Works

Three steps. No signup. No cost.

1

Forward the Email

Got a phishing email? Scam message? Suspicious attachment? Forward it to submit@blackdome.ai.

2

We Analyze & Detonate

Attachments are extracted and detonated in isolated microVMs. URLs are crawled. IOCs are extracted and classified.

3

Providers & Carriers Notified

If confirmed malicious, we notify the hosting company with evidence and identify scam callback numbers so we can report them to their VoIP carriers, including Twilio, Bandwidth, and similar providers.

Free for everyone. Built for teams when you need proof.

ThreatDrop starts as a public defense service. When your team needs submission history, evidence JSON, and webhook automation, move into Pro without changing the workflow.

ThreatDrop Free
$0

Forward suspicious emails to submit@blackdome.ai, get basic verdict handling, and contribute to the community defense pipeline.

ThreatDrop Pro
$49/mo

Get API access to your submissions, webhook delivery when analysis completes, downloadable evidence reports, and phone-number identification results.

Start Pro
ThreatDrop Enterprise pilot
Contact us

Enterprise delivery is a candidate, contact-led scoped pilot. We agree the workflow and evidence requirements before making delivery commitments.

Discuss a Pilot

Community Impact

Live totals from the ThreatDrop pipeline, refreshed every five minutes.

191
Emails Analyzed
155
Threats Detected
80
Abuse Reports Sent
11
Scam Numbers Reported
8
Sites Taken Down

Why ThreatDrop Is Different

Government Reporting

You file a report. It goes into a queue. Nothing happens for months. The phishing site stays live.

BlackDome ThreatDrop

You forward an email. We detonate it in minutes. The hosting provider gets an automated abuse report with evidence, and scam callback numbers are reported to their VoIP carriers for suspension.

Delete & Forget

You delete the email. The phishing campaign continues. Other people fall victim.

Forward & Protect

You forward the email. The threat is catalogued. The IOCs feed a global intelligence network. Everyone benefits.

Or Upload a File

Have a suspicious file? Upload it directly. Max 25MB.

Drag and drop or browse

Executables, documents, archives, scripts — all accepted

Frequently Asked Questions

Is this free?

ThreatDrop Free is free for community submissions. ThreatDrop Pro is the current paid self-service tier for teams that need customer dashboards, APIs, webhooks, and detailed observed-evidence reports. Enterprise delivery begins as a contact-led candidate pilot.

What happens when I forward an email?

We extract all attachments, URLs, and indicators of compromise (IOCs). Attachments are detonated in an isolated sandbox. If the email is confirmed malicious, we send an automated abuse report to the hosting provider with full evidence and escalate scam callback numbers to the carrier that hosts them.

How does BlackDome handle callback scams?

We automatically identify scam phone numbers, look up which carrier hosts them via Twilio, and send an abuse report to get the number suspended.

Do you share the results?

We never publish individual detonation results publicly. This prevents attackers from using BlackDome as an evasion testing service. Aggregated, anonymized threat data is shared with the community.

Do I need to create an account?

Not for ThreatDrop Free. Just forward the suspicious email to submit@blackdome.ai. If you want API access to your own submissions, webhook notifications, and downloadable evidence, create a ThreatDrop Pro account. Enterprise delivery is discussed as a contact-led candidate pilot.

How is this different from reporting to the government?

Government cybercrime portals collect reports but rarely take direct action against phishing infrastructure. BlackDome automatically identifies the hosting provider and sends a structured abuse report with evidence — leading to faster takedowns.

What file types can I submit?

All types. We specialize in executables (.exe, .dll), documents (.pdf, .docx), archives (.zip, .rar, .7z), and scripts (.js, .vbs, .ps1) — but our pipeline handles any file format.

See the Impact

Every submission makes the internet safer. Start with free forwarding or move into customer APIs and webhooks when your team needs evidence-backed workflows.