gorac.app
Appeared in the .app zone on Thursday, October 1, 2026; by the end of that day the census found active website. Full domain report
Signals, not verdicts. A domain appears here because heuristics matched its name, its infrastructure or the page it served on its first day. Where a model has looked at it, that is shown as an opinion with a confidence, not as a finding. Nothing on this page says a site is malicious. Read the evidence and decide for yourself.
Own one of these names and think the listing is wrong? Tell us and a person will look.
What matched
Model opinions
The page carries its own GoRaC branding, which matches the domain, and presents a UK governance/compliance SaaS that monitors Microsoft 365 as a product feature rather than posing as Microsoft. Its only form is an email-only GET sign-in for invited users, and the offsite link to unmuddled.com is consistent with a vendor or agency, so the scorer's 'Microsoft 365' hits are descriptive mentions, not impersonation.
The domain gorac.app impersonates Microsoft by prominently featuring 'Microsoft 365' in navigation, page content, and marketing copy ('Microsoft 365 monitoring', 'Microsoft 365, checked today'), while the page title and branding are GoRaC's own. The site has a sign-in form requesting work email credentials ('Sign in with your work email address'), posted to self with no offsite links—the sealed-room phishing pattern. The heavy focus on Microsoft 365 and Entra ID credential checks, combined with
A model looked at the screenshot and page text and wrote what it thought. It can be wrong, and it is not a finding.
What the page looked like on Thursday, October 1, 2026

Same data as JSON: /api/zone/domain/gorac.app. This page is not indexed by search engines and does not link to the site it describes.