URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 91 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Google scan id 38ca547a duration 15.16s signals 1 failing / 12
Risk score 0.02
2 / 100 · Low risk
Tags
https :// google . com
flagged registered domain path protocol / query
URL hxxps://Google[.]com
Host google[.]com
Brand Google
Screenshot https://cdn.zerophish.ai/59e92fe0-8460-4ac0-b69b-39354733534e.jpg
Scan ID 38ca547a-424d-40e1-bdfc-f70507c7d5b4
283 d ago
REVIEW google.com safe
325 d ago
REVIEW www.google.com safe
335 d ago
PHISHING www.google.com view →
Brand typo-squat detected
Registered brand domain
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Google
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render
G
Google
google.com
100%
Host google.com
Registered domain google.com
Scheme https
Content length 324025 B
HTTP 200 · text/html
JARM 0d39b39b30d30d37d20320327d20122de7c02fe862e334985aa656e5df0651
Redirect hops 2
Initial scan heuristic + LLM

Verdict: Legitimate (Google)

What the page presents itself as

  • The page title and navigation show “Google” and links such as “Gmail”, “Images”, and “Sign in”.
  • The OCR content references Google’s ecosystem, e.g., “Choose Chrome, the browser built by Google” and text about Chrome updates and terms.

Suspicious elements checked

  • Credential/credential-collection form: Not observed in the provided HTML/OCR. While there is a “Sign in” link (to https://accounts.google.com/...), there is no visible embedded login form collecting credentials on this page.
  • Fake security warnings / urgency cues: No alerts like account suspension, “verify now,” or similar urgency or threat messaging appears in the OCR text.
  • Brand mismatch indicators: The URL is https://Google.com (and the content includes multiple Google properties). The visible content strongly matches Google’s normal layout and messaging.
  • Suspicious redirects / off-domain identity: Links shown (e.g., mail.google.com, accounts.google.com, about.google.com, and store.google.com) are consistent with Google-owned domains in the HTML snippet.

Conclusion

  • Based on the strong brand consistency (Google page elements, Chrome promotional text, and links to Google-owned subdomains) and the absence of any in-page credential harvesting UI, this does not exhibit common phishing patterns.

Notes / limitations

  • The URL casing/domain formatting uses Google.com, but the links in the HTML are to standard Google domains (not lookalike domains). With the evidence provided, the page is best classified as legitimate.