URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 14 h ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand PUMA scan id 0058978f duration 25.89s signals 2 failing / 25
Risk score 0.03
3 / 100 · Low risk
Tags
https :// amzn . to /4xm4PXd
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to PUMA
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4xm4PXd
Host amzn[.]to
Brand PUMA
Screenshot https://cdn.zerophish.ai/37aa7f9f-4629-4301-8035-1e3539a45d70.jpg
Scan ID 0058978f-fc01-413c-aab4-cc816f3bd2e0
4 h ago
SAFE amzn.to safe
4 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to PUMA
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
P
PUMA
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 1889218 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (not phishing)

What the page presents

This page is a product detail page for “PUMA Unisex Adult Vellfire Walking Shoe” on an Amazon storefront. The title explicitly reads “Buy PUMA … at Amazon.in” and the OCR shows typical Amazon commerce elements like “Add to cart”, “Buy Now”, ratings, delivery location (“Delivering to Mumbai 400001”), offers, and product specifications.

Suspicious elements checked

No classic phishing social-engineering patterns were observed:

  • No credential harvesting form: the OCR shows “Hello, sign in”, but there is no visible password/login submission form on the provided content.
  • No fake security warnings or urgency tricks: there are standard shopping messages like “Only 1 left in stock.” and delivery timing, but nothing resembling account-compromise alerts or “verify your account immediately” prompts.
  • No mismatched branding / impersonation: the page consistently uses PUMA as the product brand, and the surrounding UI/terminology matches Amazon.

URL vs brand

The URL uses an Amazon redirect shortener: https://amzn.to/4xm4PXd. Since it’s on an Amazon-owned domain (via the Amazon shortener), it is consistent with the Amazon page content and does not indicate a brand impersonation from an unrelated domain.

Conclusion

Given the consistent Amazon page structure, presence of typical Amazon shopping/checkout navigation, absence of credential-collection inputs in the provided HTML/OCR, and the Amazon-related URL, this looks like a normal legitimate e-commerce page rather than a phishing site.