URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · HIGH CONFIDENCE
No phishing signals detected
Risk score
0.05
5 / 100 · Low risk
URL anatomy
https
://
amzn
.
to
/4iUTlGk
flagged
registered domain
path
protocol / query
Why this verdict
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
Visual similarity to known brand
100% structural similarity to Amazon
↑ risk
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used:
dns
network
jarm
asn
Indicators of compromise
| URL | hxxps://amzn[.]to/4iUTlGk | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/8fecc3f9-7a29-4048-a7e8-2df09b9f92ac.jpg | |
| Scan ID | 22236b51-2e92-40e7-b8a7-853fd137911c |
Related detections
|
3 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
Detection signals
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
100% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
Brand impersonation
A
Amazon
amazon.com
100%
Technical profile
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 2177349 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Analyst summary
Initial scan
Conclusion
This page appears to be a legitimate Amazon product detail page (an e-commerce listing for a “Vega Sonic Legend” motorcycle helmet), not a phishing site.
What the page presents as
- The content is consistent with Amazon’s product page structure: product title, price, delivery estimates, seller information, “Add to cart / Buy Now,” and customer reviews.
- Example product text from the page: “Vega Sonic Legend Full Face Motorcycle Helmet…”
- It also shows Amazon UI elements like “Delivering to Mumbai 400001,” “Hello, sign in,” “Account & Lists,” and “100% Purchase Protection.”
Suspicious phishing signals found
None of the typical phishing patterns are evident in the provided HTML/OCR:
- No password/credential harvesting form is shown in the provided content (the visible “Hello, sign in” indicates a login entry point, but the OCR/HTML does not include a standalone phishing login/credential form).
- No fake security alerts/urgency threats (e.g., “your account will be locked,” “verify now,” “payment required”) are present.
- The page is focused on normal shopping behaviors (size/color selection, reviews, offers).
- No mismatched branding is apparent: the UI and product presentation look like standard Amazon.
Brand and URL relationship
- Identified brand: Amazon.
- URL host: amzn.to. This is a well-known Amazon short-link domain that typically redirects to the real Amazon domain/product.
- Because the content matches Amazon’s product page (and does not mimic another brand like PayPal), there’s no strong phishing signal from the URL alone.
Verdict
Legitimate (phishing: false). The page content strongly matches an authentic Amazon product listing, and there are no clear indicators of credential theft or deceptive branding in the provided data.