The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/4zlsdX8 | |
| Host | amzn[.]to | |
| Brand | PUMA | |
| Screenshot | https://cdn.zerophish.ai/c0381c22-da63-40e9-95ac-948bde8e4b27.jpg | |
| Scan ID | 0859a86b-26b1-40df-9f30-a41dbfa8be4e |
|
3 h ago
|
SAFE | amzn.to | safe |
|
3 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 1932758 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Verdict: Legitimate (not phishing)
What the page is presenting
The URL and page content indicate an Amazon product detail page (“Buy PUMA Mens Camo Peacoat-High Risk Red Sneaker… at Amazon.in”), specifically for a PUMA men’s sneaker listing. The OCR text shows standard Amazon shopping elements like “Add to cart” and product information (price, size, product details, delivery estimates).
Suspicious elements checked
- Credential collection form: I do not see any password/login harvesting or credential-entry form in the provided HTML/OCR excerpt. The only “sign in” text shown appears as a normal Amazon header link (“Hello, sign in”).
- Fake security warnings / urgency traps: No content like “your account will be locked,” “payment overdue,” or “verify now” appears in the extracted text.
- Brand/URL mismatch: The brand presented is PUMA, and the page is hosted on amzn.to (an Amazon redirect short domain) with the title explicitly tying the product to Amazon.in. This aligns with a legitimate Amazon shopping flow.
- Redirect/impersonation indicators: The HTML looks like standard Amazon UI structure (navigation, product sections, reviews, footer), not a standalone clone site.
Why this conclusion
The combination of (1) Amazon product-page structure, (2) consistent branding in both title and body, and (3) absence of any credential-harvesting UI or phishing-style warnings strongly suggests this is a legitimate e-commerce page rather than a phishing site.
(Note: If the redirect ultimately lands on a non-Amazon domain, that would change the assessment; based on the provided content, it looks legitimate.)