The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/4x4OTsQ | |
| Host | amzn[.]to | |
| Brand | Amazon.in | |
| Screenshot | https://cdn.zerophish.ai/3f9a032b-188a-487e-93f4-8511df11f008.jpg | |
| Scan ID | 33e0ad8c-bd80-4004-913b-1c06ea633cd2 |
|
3 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 1656007 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Verdict: Legitimate (Amazon product page)
The page at https://amzn.to/4x4OTsQ is presenting an Amazon-style product detail view for “AGARO Hobby Knife Set, 29 pcs Set HK2129 : Amazon.in: Office Products” (from the HTML <title> and OCR). The content includes normal Amazon commerce elements such as delivery location (“Delivering to Mumbai 400001”), pricing, seller info (“Ships from Amazon”, “Sold by AUTHORISED SELLER”), and reviews.
Suspicious phishing signals checked
- Credential collection / login harvesting: Not observed. The OCR shows “Hello, sign in” as a normal site header/menu item, but there is no standalone phishing login form, no password field, and no form targeting credentials.
- Fake security warnings / urgency cues: No fake alerts (e.g., “account locked”, “payment failed”) or pressure tactics were found in the provided HTML/OCR. Delivery timing shown (“FREE delivery Saturday…”, “Order within 6 hrs 50 mins”) is typical Amazon checkout/delivery messaging, not a phishing prompt.
- Mismatched branding: The page branding matches Amazon conventions (navigation, sections, “Amazon’s Choice”, review layout). The product brand is AGARO, and that appears in product details normally.
- Domain mismatch concern: The link uses a shortener domain (amzn.to). While link shorteners can be used in phishing, the rendered content is fully consistent with Amazon’s product page templates, and there are no signs of a lookalike brand or credential capture in the content provided.
- Redirect/suspicious behavior: No unusual JavaScript/redirect patterns are visible in the simplified HTML excerpt (the content appears to be the standard Amazon layout and assets).
Brand identification and URL relationship
- Identified brand presented: Amazon.
- URL vs brand domain: Although the URL host is amzn.to (a redirect/short-link domain), the page content is Amazon.co.in/in-style and the OCR/HTML clearly match Amazon’s product page structure. This strongly suggests the short link resolves to a legitimate Amazon product URL.
Conclusion
Based on the absence of credential-collection forms, the lack of fake security/urgency warnings, and the strong match to Amazon’s standard product page layout and text, this looks legitimate rather than a phishing page. Confidence is high given the consistency across title, navigation, pricing/delivery elements, and review formatting.