URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL
The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
100 scans / day · free
·
typical scan 2–4 s
·
try
SAFE · HIGH CONFIDENCE
No phishing signals detected
Risk score
0.02
2 / 100 · Low risk
URL anatomy
https
://
amzn
.
to
/4gZ0iDR
flagged
registered domain
path
protocol / query
Why this verdict
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
Visual similarity to known brand
98% structural similarity to Amazon.in
↑ risk
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used:
dns
network
jarm
asn
Indicators of compromise
| URL | hxxps://amzn[.]to/4gZ0iDR | |
| Host | amzn[.]to | |
| Brand | Amazon.in | |
| Screenshot | https://cdn.zerophish.ai/2d4386f2-c8fb-4750-a587-417a2e96ef14.jpg | |
| Scan ID | a98cc4ff-5224-4834-97ef-abf005d3779f |
Related detections
|
3 h ago
|
SAFE | amzn.to | safe |
|
3 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
Detection signals
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
98% structural similarity to Amazon.in
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
Brand impersonation
A
Amazon.in
98%
Technical profile
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 1089336 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
Analyst summary
Initial scan
Verdict: Legitimate (not phishing)
This page appears to be a standard Amazon product detail page for “Buy Glamveda Rice PDRN & Collagen Night Mask…”. The URL uses a short Amazon redirect format (https://amzn.to/...) which is commonly used for Amazon share/affiliate links and typically resolves to Amazon-owned domains.
Suspicious elements checked (none convincing)
- No credential/credential-harvesting form: The OCR shows “Hello, sign in / Account & Lists” and navigation items, but there is no visible login/password form embedded in the page content provided.
- No fake security warnings / urgency traps: The page includes normal e-commerce stock messaging (“Currently unavailable. We don’t know when or if this item will be back in stock.”) rather than threat-style alerts (e.g., “account compromised”).
- Brand consistency: The content, product title, and store attribution (“Visit the GLAMVEDA Store”, “Brand GLAMVEDA”) match a typical marketplace product page; the surrounding platform branding matches Amazon UI text like “FREE Delivery by Amazon” and “100% Purchase Protection”.
-
Domain risk: While the visible URL is a short domain (
amzn.to), the HTML and assets reference Amazon infrastructure (e.g.,m.media-amazon.comandfls-eu.amazon.in), which strongly suggests it resolves to Amazon’s legitimate site.
Conclusion
Based on the strong alignment with Amazon’s standard product-page structure, lack of credential collection, and Amazon-hosted assets present in the HTML, this looks legitimate rather than a phishing attempt.