The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/4cx3PrF | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/ea02a480-48bf-43af-85a2-7f19658c4c79.jpg | |
| Scan ID | 39caf593-b178-47dc-a471-5919f970c94c |
|
3 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 809179 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
The page presents itself as Amazon.in, showing typical Amazon UI elements such as “Hello, sign in”, “Account & Lists”, category navigation, and multiple product search results with Amazon delivery and pricing messaging.
The URL uses a short link domain (amzn.to), but the content and branding in the rendered HTML/OCR strongly match Amazon’s layout and text (e.g., Amazon Pay ICICI card messaging, category sidebar, and footer links like “Conditions of Use & Sale” and “Privacy Notice”). There are no visible credential-harvesting components in the provided HTML/OCR (no password/login form shown in the extracted content), and there are no phishing-style urgency or fake security warnings.
Given the strong structural/visual resemblance to Amazon and absence of credential forms or deceptive security prompts, this looks like a legitimate Amazon shopping/search page delivered via a redirect/short link rather than a phishing page.