The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/4xm4PXd | |
| Host | amzn[.]to | |
| Brand | PUMA | |
| Screenshot | https://cdn.zerophish.ai/37aa7f9f-4629-4301-8035-1e3539a45d70.jpg | |
| Scan ID | 0058978f-fc01-413c-aab4-cc816f3bd2e0 |
|
4 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 1889218 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Verdict: Legitimate (not phishing)
What the page presents
This page is a product detail page for “PUMA Unisex Adult Vellfire Walking Shoe” on an Amazon storefront. The title explicitly reads “Buy PUMA … at Amazon.in” and the OCR shows typical Amazon commerce elements like “Add to cart”, “Buy Now”, ratings, delivery location (“Delivering to Mumbai 400001”), offers, and product specifications.
Suspicious elements checked
No classic phishing social-engineering patterns were observed:
- No credential harvesting form: the OCR shows “Hello, sign in”, but there is no visible password/login submission form on the provided content.
- No fake security warnings or urgency tricks: there are standard shopping messages like “Only 1 left in stock.” and delivery timing, but nothing resembling account-compromise alerts or “verify your account immediately” prompts.
- No mismatched branding / impersonation: the page consistently uses PUMA as the product brand, and the surrounding UI/terminology matches Amazon.
URL vs brand
The URL uses an Amazon redirect shortener: https://amzn.to/4xm4PXd. Since it’s on an Amazon-owned domain (via the Amazon shortener), it is consistent with the Amazon page content and does not indicate a brand impersonation from an unrelated domain.
Conclusion
Given the consistent Amazon page structure, presence of typical Amazon shopping/checkout navigation, absence of credential-collection inputs in the provided HTML/OCR, and the Amazon-related URL, this looks like a normal legitimate e-commerce page rather than a phishing site.