URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 33 d ago. Click Reanalyze to run a fresh scan.
SAFE · LOW CONFIDENCE

No phishing signals detected

brand Unknown scan id 63b83615 duration 11.66s signals 1 failing / 25
Risk score 0.25
25 / 100 · Low risk
Tags
https :// fkrt . to /4Yr7rLrA
flagged registered domain path protocol / query
×
Email-auth posture (SPF/DMARC)
No DMARC record — domain trivially spoofable in phishing email
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://fkrt[.]to/4Yr7rLrA
Host fkrt[.]to
Screenshot https://cdn.zerophish.ai/fb99ff9c-0c78-44ea-84b4-46f2fffb524b.jpg
Scan ID 63b83615-7e71-4053-8008-aa072ee7685e
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

Host fkrt.to
Registered domain fkrt.to
Scheme https
Content length 66735 B
HTTP 200 · text/html
DMARC policy none
SPF policy none
MX records none
Initial scan heuristic + LLM

The page presents itself as a bot-detection / browser verification interstitial for the domain fkrt.to. It shows generic messaging (“Performing security verification” / “This website uses a security service to protect against malicious bots”) and a Cloudflare-style footer (“Performance and Security by Cloudflare”). There is no visible login or credential-collection form in the provided HTML/OCR, and there is no indication of mismatched branding or an impersonated third-party brand.

Because the content is only a generic verification gate and not a credential-harvesting flow, the evidence for phishing is weak. However, the URL is not a known first-party brand domain (it is an unrelated short domain), so if this challenge appears unexpectedly in a context that should be for a specific brand, it could still be part of a malicious redirect chain; based on the provided material alone, this looks more consistent with a legitimate anti-bot page than a phishing form.