Suspicious email? Forward it. Get a verdict.
ThreatDrop detonates suspicious emails in isolated environments and returns structured evidence reports. No signup required for community access — just forward to submit@blackdome.ai.
Most email analysis tools tell you an attachment is bad. ThreatDrop shows you what it does — full detonation report with IOCs, behaviour analysis, and evidence you can act on.
What Security Teams Get
ThreatDrop is designed for the real handoff from suspicious email to analyst workflow, ticket, or takedown action.
Submission History
List your own forwarded submissions with verdict, confidence, risk score, detonation status, and evidence links instead of relying on a one-off mailbox response.
Evidence Reports
Download structured JSON evidence containing normalized email content, detonations, abuse reports, and phone-report results for case files or downstream tooling.
Webhook Delivery
Trigger internal workflows when analysis completes by receiving an `analysis_complete` POST with verdict, confidence, detonation counts, and the evidence URL.
How ThreatDrop Works
The free and paid product tiers share the same intake path. The difference is what your team can do with the results.
Forward the message
Send the suspicious email to submit@blackdome.ai from Gmail, Outlook, Apple Mail, or your preferred client.
BlackDome analyzes
ThreatDrop extracts URLs, attachments, and indicators, then detonates suspicious assets in isolated environments.
Notification attempts are recorded
ThreatDrop records provider and carrier notification attempts, replies, and observed takedown-workflow status when available.
Your team consumes the evidence
Paid plans expose customer dashboards, APIs, webhooks, and downloadable evidence records tied to your own submissions.
Built For
Typical teams using ThreatDrop Pro or discussing a scoped pilot.
Choose Your ThreatDrop Tier
Start with free forwarding, then upgrade when your team needs customer-visible evidence and automation.
Free
Community submission path for individuals and early evaluations.
- Forward emails to submit@blackdome.ai
- Basic verdict visibility
- Public community impact
- No API key required
Pro
Customer API access, evidence JSON, and webhook-driven workflows.
- Submission API access
- Webhook notifications
- Detailed evidence reports
- Priority analysis queue
- Phone number identification results
Enterprise pilot
Contact-led discussion for a scoped ThreatDrop delivery pilot.
- Everything in Pro
- Scoped workflow review
- Candidate delivery design
- Observed-evidence reporting
API Preview
What your first ThreatDrop automation can look like.
ThreatDrop docs include forwarding instructions, webhook payload examples, and evidence-report structure.
Start with forwarding. Automate when the team needs it.
Forward suspicious mail for free, then turn the same intake path into dashboards, APIs, and webhooks when you need scale and repeatability.