The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/464PBuw | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/1ef9ee4f-ae41-4a48-a9b8-830206d96bc4.jpg | |
| Scan ID | 44848cdf-8151-4025-837b-669845a616c4 |
|
4 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 2054157 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Verdict: Legitimate (Amazon product page)
What the page is presenting
The URL and page content present a normal Amazon e-commerce product listing. The HTML title and OCR text show a specific product and Amazon layout elements (e.g., “Hello, sign in”, “Add to cart”, “Buy Now”, “Delivering to Mumbai 400001”, “Secure transaction”, product price blocks, and seller/fulfillment info).
Suspicious elements checked
- Credential/credential-harvesting form: I do not see a password, login submission, or standalone credential-collection form on the page excerpt. The “Hello, sign in” appears as a header/navigation element rather than an external login harvest form.
- Fake security warnings / urgency cues: No “account will be closed”, “verify now”, “suspicious activity”, or similar phishing-style alerts are present in the provided OCR text.
- Mismatched branding / impersonation: The page consistently displays Amazon navigation/footer and an Amazon-like product page structure.
-
Unusual domain/redirect behavior: The visible content and embedded assets refer to Amazon infrastructure (e.g.,
m.media-amazon.comandfls-eu.amazon.in).
Brand identification & URL relationship
The page presents itself as Amazon. While the displayed link is a short URL (https://amzn.to/...), the HTML includes Amazon domains (amazon.in, m.media-amazon.com, fls-eu.amazon.in), which is consistent with a legitimate Amazon redirect/short-link mechanism.
Conclusion
Given the strong consistency between Amazon branding, Amazon-hosted assets/domains inside the HTML, and the absence of credential forms or phishing-style warnings, this looks like a legitimate Amazon product page rather than a phishing site.