URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 1 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon scan id 93758aea duration 11.26s signals 2 failing / 25
Risk score 0.06
6 / 100 · Low risk
Tags
https :// amzn . to /4iO0l80
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
98% structural similarity to Amazon
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4iO0l80
Host amzn[.]to
Brand Amazon
Screenshot https://cdn.zerophish.ai/dcdab7d1-3656-41f4-b56f-76c736b9be79.jpg
Scan ID 93758aea-06ef-41ef-81da-06eaf9fd9f07
3 h ago
SAFE amzn.to safe
3 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
98% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon
amazon.com
98%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 468132 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Assessment

The page presents itself as an Amazon.in shopping/search results page (e.g., “Amazon.in” in the HTML <title>, “Delivering to Mumbai 400001”, category navigation like “Electronics”, and product listings such as “Mothca Military-Grade Tempered Glass Screen Protector…”).

Suspicious elements found (phishing indicators)

  • No credential harvesting form observed in the provided HTML/OCR. There is a sign-in link (“Hello, sign in”), but no visible password/email input fields or a fake login form.
  • No urgent/fake security warnings (no “account locked”, “verify now”, “suspicious activity”, etc.) in the OCR text.
  • No mismatched branding: the content and UI strongly align with Amazon’s normal layout and terminology (e.g., “Returns & Orders”, “Add to cart”, “Prime Video”, “Conditions of Use & Sale”).

URL vs. brand check

  • The URL is https://amzn.to/4iO0l80. This is a known Amazon short-link domain used for redirection/tracking.
  • The page content still matches Amazon.in branding and structure (“Amazon.in”, delivery location prompt, Amazon footer). While the short link could, in theory, redirect to something else, the rendered page shown here is consistent with legitimate Amazon UI.

Conclusion

Verdict: legitimate (not phishing). The rendered content is a standard Amazon shopping/search experience with no credential form, no security scare text, and no clear brand mismatch. Confidence is high given the strong structural/wording alignment with Amazon and the absence of common phishing elements in the provided material.