URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · HIGH CONFIDENCE
No phishing signals detected
Risk score
0.03
3 / 100 · Low risk
URL anatomy
https
://
amzn
.
to
/4fYQOrK
flagged
registered domain
path
protocol / query
Why this verdict
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
Visual similarity to known brand
100% structural similarity to Amazon
↑ risk
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used:
dns
network
jarm
asn
Indicators of compromise
| URL | hxxps://amzn[.]to/4fYQOrK | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/2f035f35-5b33-40a3-9cee-9f02b9d105ee.jpg | |
| Scan ID | 7e01dfd7-16fb-40d8-ac44-869420bf656b |
Related detections
|
3 h ago
|
SAFE | amzn.to | safe |
|
3 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
Detection signals
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
100% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
Brand impersonation
A
Amazon
amazon.com
100%
Technical profile
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 1490596 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Analyst summary
Initial scan
Verdict: Legitimate (Not Phishing)
What the page presents itself as
-
The URL resolves to an Amazon short link:
https://amzn.to/4fYQOrK. - The HTML/OCR content is a standard Amazon product detail page for an item titled “Rangriti Women Viscose Printed Suit Set” (including typical sections like “About this item”, product specs, delivery location, and Amazon footer links).
Suspicious elements checked (none found)
- No credential/credential-harvesting form: The OCR shows “Hello, sign in” and navigation items, but no password/login submission fields are present in the provided HTML/OCR snippet.
- No fake security warnings or urgency scams: There are no messages like “account compromised”, “verify now”, or similar alarmist prompts.
- No mismatched branding: Content consistently uses Amazon layout/terminology (e.g., “Secure transaction”, “Add to Wish List”, Amazon footer).
-
No unusual redirect behavior evidence in the snippet: While the URL uses
amzn.to, that is an Amazon-owned redirect mechanism; the rendered content matches Amazon’s product page structure.
Brand identification & URL relationship
- Identified brand: Amazon.
-
The provided URL is an Amazon-owned short domain (
amzn.to), and the rendered page content is consistent with Amazon product-page DOM elements, so there’s no sign of lookalike branding on a foreign domain.
Why this conclusion
- The page matches a normal Amazon product listing (product title/specs, Amazon UI sections, and footer).
- The absence of login/password forms and the absence of phishing-style social engineering cues strongly indicate this is not a phishing page.