URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 7 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon scan id 44848cdf duration 17.57s signals 2 failing / 25
Risk score 0.02
2 / 100 · Low risk
Tags
https :// amzn . to /464PBuw
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to Amazon
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/464PBuw
Host amzn[.]to
Brand Amazon
Screenshot https://cdn.zerophish.ai/1ef9ee4f-ae41-4a48-a9b8-830206d96bc4.jpg
Scan ID 44848cdf-8151-4025-837b-669845a616c4
4 h ago
SAFE amzn.to safe
4 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon
amazon.com
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 2054157 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (Amazon product page)

What the page is presenting

The URL and page content present a normal Amazon e-commerce product listing. The HTML title and OCR text show a specific product and Amazon layout elements (e.g., “Hello, sign in”, “Add to cart”, “Buy Now”, “Delivering to Mumbai 400001”, “Secure transaction”, product price blocks, and seller/fulfillment info).

Suspicious elements checked

  • Credential/credential-harvesting form: I do not see a password, login submission, or standalone credential-collection form on the page excerpt. The “Hello, sign in” appears as a header/navigation element rather than an external login harvest form.
  • Fake security warnings / urgency cues: No “account will be closed”, “verify now”, “suspicious activity”, or similar phishing-style alerts are present in the provided OCR text.
  • Mismatched branding / impersonation: The page consistently displays Amazon navigation/footer and an Amazon-like product page structure.
  • Unusual domain/redirect behavior: The visible content and embedded assets refer to Amazon infrastructure (e.g., m.media-amazon.com and fls-eu.amazon.in).

Brand identification & URL relationship

The page presents itself as Amazon. While the displayed link is a short URL (https://amzn.to/...), the HTML includes Amazon domains (amazon.in, m.media-amazon.com, fls-eu.amazon.in), which is consistent with a legitimate Amazon redirect/short-link mechanism.

Conclusion

Given the strong consistency between Amazon branding, Amazon-hosted assets/domains inside the HTML, and the absence of credential forms or phishing-style warnings, this looks like a legitimate Amazon product page rather than a phishing site.