URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 24 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon.in scan id 33e0ad8c duration 21.58s signals 2 failing / 25
Risk score 0.02
2 / 100 · Low risk
Tags
https :// amzn . to /4x4OTsQ
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to Amazon.in
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4x4OTsQ
Host amzn[.]to
Brand Amazon.in
Screenshot https://cdn.zerophish.ai/3f9a032b-188a-487e-93f4-8511df11f008.jpg
Scan ID 33e0ad8c-bd80-4004-913b-1c06ea633cd2
3 h ago
SAFE amzn.to safe
4 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Amazon.in
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon.in
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 1656007 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (Amazon product page)

The page at https://amzn.to/4x4OTsQ is presenting an Amazon-style product detail view for “AGARO Hobby Knife Set, 29 pcs Set HK2129 : Amazon.in: Office Products” (from the HTML <title> and OCR). The content includes normal Amazon commerce elements such as delivery location (“Delivering to Mumbai 400001”), pricing, seller info (“Ships from Amazon”, “Sold by AUTHORISED SELLER”), and reviews.

Suspicious phishing signals checked

  • Credential collection / login harvesting: Not observed. The OCR shows “Hello, sign in” as a normal site header/menu item, but there is no standalone phishing login form, no password field, and no form targeting credentials.
  • Fake security warnings / urgency cues: No fake alerts (e.g., “account locked”, “payment failed”) or pressure tactics were found in the provided HTML/OCR. Delivery timing shown (“FREE delivery Saturday…”, “Order within 6 hrs 50 mins”) is typical Amazon checkout/delivery messaging, not a phishing prompt.
  • Mismatched branding: The page branding matches Amazon conventions (navigation, sections, “Amazon’s Choice”, review layout). The product brand is AGARO, and that appears in product details normally.
  • Domain mismatch concern: The link uses a shortener domain (amzn.to). While link shorteners can be used in phishing, the rendered content is fully consistent with Amazon’s product page templates, and there are no signs of a lookalike brand or credential capture in the content provided.
  • Redirect/suspicious behavior: No unusual JavaScript/redirect patterns are visible in the simplified HTML excerpt (the content appears to be the standard Amazon layout and assets).

Brand identification and URL relationship

  • Identified brand presented: Amazon.
  • URL vs brand domain: Although the URL host is amzn.to (a redirect/short-link domain), the page content is Amazon.co.in/in-style and the OCR/HTML clearly match Amazon’s product page structure. This strongly suggests the short link resolves to a legitimate Amazon product URL.

Conclusion

Based on the absence of credential-collection forms, the lack of fake security/urgency warnings, and the strong match to Amazon’s standard product page layout and text, this looks legitimate rather than a phishing page. Confidence is high given the consistency across title, navigation, pricing/delivery elements, and review formatting.