URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 7 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon.in scan id b66abc65 duration 19.4s signals 2 failing / 25
Risk score 0.06
6 / 100 · Low risk
Tags
https :// amzn . to /4h9Xvbd
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to Amazon.in
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4h9Xvbd
Host amzn[.]to
Brand Amazon.in
Screenshot https://cdn.zerophish.ai/1c406faa-85ad-4bf6-a8b2-922ca7beed01.jpg
Scan ID b66abc65-669b-4369-a7c2-60b492ae3af6
3 h ago
SAFE amzn.to safe
3 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Amazon.in
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon.in
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 2330727 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (phishing = false)

What the page is presenting

This appears to be a normal Amazon product detail page for a SanDisk USB flash drive. The content includes standard Amazon elements like navigation, “Hello, sign in”, delivery/location, product title, price, warranty, and purchase options.

Suspicious elements checked (none found)

  • No credential harvesting UI: the provided HTML/OCR shows “Hello, sign in” and “Account & Lists”, but there is no visible password/login form or input fields in the excerpt.
  • No fake security/urgency warnings: there are no messages like account suspension, verification required, or “unusual activity” prompts.
  • No off-brand payment capture: purchase sections show Amazon-like wording such as “Secure transaction”, “Payment”, “Pay on Delivery”, and “Add to cart / Buy Now”, without redirecting into a different branded checkout.
  • No mismatched branding for the identified site: the page’s branding and UI are consistent with Amazon.

Brand identification and URL relationship

  • Identified brand: Amazon.
  • URL: https://amzn.to/4h9Xvbd is a URL shortener domain commonly used for Amazon redirects. While the host is not amazon.in directly, the page content matches Amazon’s product page structure and text (e.g., “Amazon.in: Electronics”, standard Amazon layout and product details).

Why this conclusion

The page looks like a real e-commerce product listing (SanDisk Ultra Curve flash drive) rendered with Amazon’s typical UI and copy. Most phishing indicators—credential forms, fake security alerts, and inconsistent branding—are absent in the provided HTML/OCR, so the safest assessment is legitimate with high confidence.