The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/4wsqZq7 | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/ae2d9fb0-08b8-4bf9-b313-d0288931e6a5.jpg | |
| Scan ID | 85c29395-43f3-425b-a698-ceaa8ef3c90c |
|
4 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 1487252 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Verdict: Legitimate (Amazon product page)
The page at https://amzn.to/4wsqZq7 presents itself as an Amazon.in listing for “F Gear Polaris Black 37L School Backpack.” The visible content includes typical Amazon e-commerce elements such as “Add to cart,” “Buy Now,” seller/shipping blocks (“Ships from Amazon” / “Sold by RetailEZ Pvt Ltd”), price/MRP details, delivery estimates, and standard footer links (“Conditions of Use & Sale”, “Privacy Notice”, © 1996–2026 Amazon.com”).
Suspicious elements checked
- Credential-collection form: None observed. The OCR/HTML excerpt shows purchase UI (“Add to cart / Buy Now”) and product details, not a login/password form.
- Fake security warnings / urgency scams: None present (no account-hold notices, “verify now,” or unusual “your account will be closed” messaging).
- Brand mismatch: The page branding and text strongly match Amazon’s standard storefront formatting.
- Domain structure / redirect risk: The URL uses a shortener (amzn.to). While short links can be abused, in this case the page content itself is clearly Amazon (amazon.in language/copy, Amazon footer, product listing layout). Short URLs alone are not enough to mark phishing when the rendered page is consistent.
- Favicon impersonation: No favicon data provided; no evidence in the provided text that an unrelated brand icon is being imitated.
Brand identification and URL relationship
- Identified brand: Amazon.
- URL vs brand domain: Although the URL host is amzn.to (a redirect/short-link domain), the rendered content is consistent with Amazon.in. This aligns with legitimate Amazon link redirection behavior.
Conclusion
Overall, the evidence points to a normal Amazon product detail page. The absence of any credential form or scam-style warnings, combined with strong Amazon UI/product-page consistency, supports a legitimate classification with high confidence.