The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/45ShoOr | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/21fa1f9a-3dbc-47e5-805f-a9bec6ba860e.jpg | |
| Scan ID | 5438524b-1913-4db9-a565-da2e51c1fbec |
|
4 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 1591660 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
The page presents itself as a legitimate Amazon product listing (“Van Heusen … : Amazon.in”) with typical e-commerce elements like price, delivery, and an “Add to cart”/“Buy Now” flow. The URL is an Amazon short link (amzn.to) and the HTML content strongly matches Amazon’s structure and navigation (e.g., “Delivering to Mumbai 400001”, “Hello, sign in”, “Secure transaction”).
No phishing-specific social-engineering indicators are visible in the provided HTML/OCR: there are no fake security alerts, no account-compromise warnings, and no credential/password collection form shown (only standard sign-in navigation). While the domain is a URL shortener, it still resolves within Amazon’s ecosystem and there is no mismatch in branding cues between the identified brand (Amazon) and the content rendered.
Overall, the evidence supports a legitimate Amazon product page rather than a phishing site.