URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 24 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon scan id 85c29395 duration 16.92s signals 2 failing / 25
Risk score 0.05
5 / 100 · Low risk
Tags
https :// amzn . to /4wsqZq7
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to Amazon
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4wsqZq7
Host amzn[.]to
Brand Amazon
Screenshot https://cdn.zerophish.ai/ae2d9fb0-08b8-4bf9-b313-d0288931e6a5.jpg
Scan ID 85c29395-43f3-425b-a698-ceaa8ef3c90c
4 h ago
SAFE amzn.to safe
4 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon
amazon.com
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 1487252 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (Amazon product page)

The page at https://amzn.to/4wsqZq7 presents itself as an Amazon.in listing for “F Gear Polaris Black 37L School Backpack.” The visible content includes typical Amazon e-commerce elements such as “Add to cart,” “Buy Now,” seller/shipping blocks (“Ships from Amazon” / “Sold by RetailEZ Pvt Ltd”), price/MRP details, delivery estimates, and standard footer links (“Conditions of Use & Sale”, “Privacy Notice”, © 1996–2026 Amazon.com”).

Suspicious elements checked

  • Credential-collection form: None observed. The OCR/HTML excerpt shows purchase UI (“Add to cart / Buy Now”) and product details, not a login/password form.
  • Fake security warnings / urgency scams: None present (no account-hold notices, “verify now,” or unusual “your account will be closed” messaging).
  • Brand mismatch: The page branding and text strongly match Amazon’s standard storefront formatting.
  • Domain structure / redirect risk: The URL uses a shortener (amzn.to). While short links can be abused, in this case the page content itself is clearly Amazon (amazon.in language/copy, Amazon footer, product listing layout). Short URLs alone are not enough to mark phishing when the rendered page is consistent.
  • Favicon impersonation: No favicon data provided; no evidence in the provided text that an unrelated brand icon is being imitated.

Brand identification and URL relationship

  • Identified brand: Amazon.
  • URL vs brand domain: Although the URL host is amzn.to (a redirect/short-link domain), the rendered content is consistent with Amazon.in. This aligns with legitimate Amazon link redirection behavior.

Conclusion

Overall, the evidence points to a normal Amazon product detail page. The absence of any credential form or scam-style warnings, combined with strong Amazon UI/product-page consistency, supports a legitimate classification with high confidence.