URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 4 h ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon scan id b6d82cb0 duration 16.68s signals 2 failing / 25
Risk score 0.05
5 / 100 · Low risk
Tags
https :// amzn . to /46RbvS7
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to Amazon
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/46RbvS7
Host amzn[.]to
Brand Amazon
Screenshot https://cdn.zerophish.ai/545c8707-a21f-4799-84f6-2a4555c364d0.jpg
Scan ID b6d82cb0-1f16-4d20-b465-41ca7a08ac1c
3 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon
amazon.com
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 1546022 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (not a phishing page)

What the page is presenting

The URL and page content identify this as an Amazon.in product detail page for “Buy Judge by Prestige Stainless Steel Pan Spoon 1.5 (32cm) Online at Low Prices in India - Amazon.in”. The OCR shows typical Amazon e-commerce elements such as product title, price, delivery estimates, “Add to cart”, and seller/fulfillment information.

Suspicious elements checked

I looked for common phishing/social-engineering patterns (credential harvesting forms, fake security alerts, urgency designed to prompt logins, and brand spoofing). In the provided HTML/OCR:

  • No credential/credential-collection form is shown (no password/email inputs or login submission form in the excerpt). The only “Hello, sign in” text appears in the site header/navigation, consistent with normal Amazon UI rather than a harvesting page.
  • No fake security warning/alert is present (no messages like “account compromised”, “verify now”, “suspended”, etc.).
  • No payment-redirection trick is visible in the excerpt. The page includes normal checkout-related labels like “Secure transaction”, but no suspicious off-domain payment capture.
  • Branding consistency: the page presents the Amazon brand and the OCR repeatedly references Amazon navigation, departments, and footer/legal copy (“© 1996-2026, Amazon.com, Inc.”).

URL vs. brand relationship

The URL is https://amzn.to/46RbvS7 (a known Amazon short-link domain pattern). The page title explicitly says Amazon.in, and the body text strongly matches Amazon’s product-page template and terminology. There is no indication of a mismatch such as a PayPal-branded login on a non-PayPal domain.

Conclusion

Given the strong consistency between the Amazon-branded content and the Amazon short-link URL, and because there are no credential-harvesting or urgency/fake-warning indicators in the provided content, this appears to be a legitimate Amazon product page, not a phishing site.