URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 29 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand PUMA scan id 0859a86b duration 15.95s signals 2 failing / 25
Risk score 0.06
6 / 100 · Low risk
Tags
https :// amzn . to /4zlsdX8
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to PUMA
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4zlsdX8
Host amzn[.]to
Brand PUMA
Screenshot https://cdn.zerophish.ai/c0381c22-da63-40e9-95ac-948bde8e4b27.jpg
Scan ID 0859a86b-26b1-40df-9f30-a41dbfa8be4e
3 h ago
SAFE amzn.to safe
3 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to PUMA
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
P
PUMA
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 1932758 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (not phishing)

What the page is presenting

The URL and page content indicate an Amazon product detail page (“Buy PUMA Mens Camo Peacoat-High Risk Red Sneaker… at Amazon.in”), specifically for a PUMA men’s sneaker listing. The OCR text shows standard Amazon shopping elements like “Add to cart” and product information (price, size, product details, delivery estimates).

Suspicious elements checked

  • Credential collection form: I do not see any password/login harvesting or credential-entry form in the provided HTML/OCR excerpt. The only “sign in” text shown appears as a normal Amazon header link (“Hello, sign in”).
  • Fake security warnings / urgency traps: No content like “your account will be locked,” “payment overdue,” or “verify now” appears in the extracted text.
  • Brand/URL mismatch: The brand presented is PUMA, and the page is hosted on amzn.to (an Amazon redirect short domain) with the title explicitly tying the product to Amazon.in. This aligns with a legitimate Amazon shopping flow.
  • Redirect/impersonation indicators: The HTML looks like standard Amazon UI structure (navigation, product sections, reviews, footer), not a standalone clone site.

Why this conclusion

The combination of (1) Amazon product-page structure, (2) consistent branding in both title and body, and (3) absence of any credential-harvesting UI or phishing-style warnings strongly suggests this is a legitimate e-commerce page rather than a phishing site.

(Note: If the redirect ultimately lands on a non-Amazon domain, that would change the assessment; based on the provided content, it looks legitimate.)