URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 24 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Dove scan id 9cae5a04 duration 18.07s signals 2 failing / 25
Risk score 0.05
5 / 100 · Low risk
Tags
https :// amzn . to /4glkJe1
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to Dove
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4glkJe1
Host amzn[.]to
Brand Dove
Screenshot https://cdn.zerophish.ai/eed8f98a-10a5-4c18-9fa9-6af6402970fc.jpg
Scan ID 9cae5a04-a87c-4110-ab66-e01172c0e42f
3 h ago
SAFE amzn.to safe
3 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Dove
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
D
Dove
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 2151049 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (not phishing)

What the page presents

The URL resolves to an Amazon product detail page titled: “Buy Dove Fresh Moisture Beauty Bathing Bar… Online at Low Prices in India - Amazon.in”. The content is consistent with a standard Amazon listing: product title, seller information (“Ships from Amazon” / “Sold by RK World Infocom Pvt Ltd”), pricing, delivery estimate, reviews, and Amazon footer links.

Suspicious elements checked (and not found)

  • No credential/identity collection: The OCR shows “Hello, sign in” and “Account & Lists”, but there is no visible password/login form or payment credential capture on the provided HTML/OCR excerpt.
  • No fake security urgency: There are no messages like account compromise warnings, “verify now,” or threats of account closure.
  • No mismatched branding/phoney domain: Although the short URL is amzn.to/..., the page content and metadata are clearly for Amazon and the product brand is Dove (e.g., “Brand Dove”, “Top Brand Dove”). This is not a classic lookalike of a financial brand or a fake checkout page.

Brand and URL relationship

  • Identified brand (presented product brand): Dove.
  • The page is hosted under Amazon’s infrastructure (product listing page elements, Amazon footer, Amazon delivery language). The short-link host amzn.to is consistent with legitimate Amazon URL redirection, not an unrelated domain attempting to impersonate Dove/PayPal/etc.

Conclusion

Based on the strong presence of authentic Amazon e-commerce page structure (product details, seller/delivery/reviews) and the absence of credential-collection or urgency-based social engineering cues, this page is highly likely legitimate and not phishing.