The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://www[.]instagram[.]com | |
| Host | www[.]instagram[.]com | |
| Registered domain | instagram[.]com | |
| Brand | ||
| Screenshot | https://cdn.zerophish.ai/bf372073-bc9d-40db-838c-ffd2c807e960.jpg | |
| Scan ID | 272f325b-9e57-433e-ac11-eeb3cd1c2694 |
|
76 d ago
|
SAFE | www.instagram.com | safe |
|
91 d ago
|
SAFE | www.instagram.com | safe |
|
245 d ago
|
PHISHING | instagram.com | view → |
|
401 d ago
|
REVIEW | www.instagram.com | safe |
| Host | www.instagram.com |
| Registered domain | instagram.com |
| Scheme | https |
| Content length | 443778 B |
| HTTP | 200 · text/html |
| JARM | 7939b39b37937930320320320320128c19258acd09ccdea8faad630541ff7e |
| Redirect hops | 1 |
Page presented as
The page is a login entry point for Instagram, with the heading/text such as “Log into Instagram” and a standard login form.
Suspicious elements checked (phishing indicators)
- Credential collection present (legit use): The OCR shows “Mobile number, username or email” and “Password” with a “Log in” button. This is a credential form, but it matches Instagram’s expected authentication flow.
- No fake security warnings / urgency cues: The provided OCR/HTML does not contain alerts like “account compromised,” “verify urgently,” or other fake warning copy.
- Brand/URL alignment: The URL is https://www.instagram.com, which matches the Instagram brand domain. There is no evidence of a lookalike domain or mismatched branding.
- No evidence of favicon impersonation: No favicon data is present in the provided snippet to suggest impersonation of another brand.
Verdict reasoning
Based on the correct Instagram domain and the standard, brand-consistent login UI, the page most closely resembles a legitimate Instagram login rather than an impersonation site. While it does request credentials (which is common in phishing), there are no additional phishing hallmarks in the provided content (no fake alerts, no mismatched domain branding, no suspicious redirects shown).
Conclusion
Legitimate (phishing = false).