The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/4iO0l80 | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/dcdab7d1-3656-41f4-b56f-76c736b9be79.jpg | |
| Scan ID | 93758aea-06ef-41ef-81da-06eaf9fd9f07 |
|
3 h ago
|
SAFE | amzn.to | safe |
|
3 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 468132 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Assessment
The page presents itself as an Amazon.in shopping/search results page (e.g., “Amazon.in” in the HTML <title>, “Delivering to Mumbai 400001”, category navigation like “Electronics”, and product listings such as “Mothca Military-Grade Tempered Glass Screen Protector…”).
Suspicious elements found (phishing indicators)
- No credential harvesting form observed in the provided HTML/OCR. There is a sign-in link (“Hello, sign in”), but no visible password/email input fields or a fake login form.
- No urgent/fake security warnings (no “account locked”, “verify now”, “suspicious activity”, etc.) in the OCR text.
- No mismatched branding: the content and UI strongly align with Amazon’s normal layout and terminology (e.g., “Returns & Orders”, “Add to cart”, “Prime Video”, “Conditions of Use & Sale”).
URL vs. brand check
-
The URL is
https://amzn.to/4iO0l80. This is a known Amazon short-link domain used for redirection/tracking. - The page content still matches Amazon.in branding and structure (“Amazon.in”, delivery location prompt, Amazon footer). While the short link could, in theory, redirect to something else, the rendered page shown here is consistent with legitimate Amazon UI.
Conclusion
Verdict: legitimate (not phishing). The rendered content is a standard Amazon shopping/search experience with no credential form, no security scare text, and no clear brand mismatch. Confidence is high given the strong structural/wording alignment with Amazon and the absence of common phishing elements in the provided material.