The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://fkrt[.]to/4Yr7rLrA | |
| Host | fkrt[.]to | |
| Screenshot | https://cdn.zerophish.ai/fb99ff9c-0c78-44ea-84b4-46f2fffb524b.jpg | |
| Scan ID | 63b83615-7e71-4053-8008-aa072ee7685e |
No brand impersonation signals available.
| Host | fkrt.to |
| Registered domain | fkrt.to |
| Scheme | https |
| Content length | 66735 B |
| HTTP | 200 · text/html |
| DMARC policy | none |
| SPF policy | none |
| MX records | none |
The page presents itself as a bot-detection / browser verification interstitial for the domain fkrt.to. It shows generic messaging (“Performing security verification” / “This website uses a security service to protect against malicious bots”) and a Cloudflare-style footer (“Performance and Security by Cloudflare”). There is no visible login or credential-collection form in the provided HTML/OCR, and there is no indication of mismatched branding or an impersonated third-party brand.
Because the content is only a generic verification gate and not a credential-harvesting flow, the evidence for phishing is weak. However, the URL is not a known first-party brand domain (it is an unrelated short domain), so if this challenge appears unexpectedly in a context that should be for a specific brand, it could still be part of a malicious redirect chain; based on the provided material alone, this looks more consistent with a legitimate anti-bot page than a phishing form.