The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/4xH56o4 | |
| Host | amzn[.]to | |
| Brand | Amazon | |
| Screenshot | https://cdn.zerophish.ai/526eb598-3fdd-4a6c-bfd9-ce5403a4fab8.jpg | |
| Scan ID | c51c8fb8-94fc-42c4-a66d-b809a761909c |
|
3 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 714615 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
The page presents itself as an Amazon.in search/browsing experience (“Delivering to Mumbai 400001”, “Hello, sign in”, “10 results for “uspa””, and Amazon category navigation). The URL uses a shortener domain (amzn.to), but the content and referenced Amazon assets/sprite URLs strongly match Amazon’s legitimate storefront layout.
Suspicious phishing cues such as credential-harvesting forms, urgent security warnings, or mismatched branding are not present in the provided HTML/OCR. The OCR shows standard Amazon UI elements and no password/login form submission fields.
Given the strong visual/structural alignment with Amazon and the absence of typical phishing elements, this is very likely a legitimate Amazon page reached via a redirect/short link.