URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 15 h ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon scan id e6f7434a duration 14.06s signals 2 failing / 25
Risk score 0.06
6 / 100 · Low risk
Tags
https :// amzn . to /3UOEymI
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
99% structural similarity to Amazon
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/3UOEymI
Host amzn[.]to
Brand Amazon
Screenshot https://cdn.zerophish.ai/7bf32500-5d10-4c7a-895e-ccd630388907.jpg
Scan ID e6f7434a-abd0-4173-b775-a65d593654a7
4 h ago
SAFE amzn.to safe
4 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
15 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
99% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon
amazon.com
99%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 1285840 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

What the page is presenting

The URL goes to an Amazon product page (title/heading in HTML and OCR text: “Buy Reebok Men Grey Running Shoes at Amazon.in” and “Reebok Mens Iq6980 Sneaker”), showing typical Amazon elements like delivery info, price, EMI options, seller (“Sold by Cocoblu Retail”), and an “Add to cart / Buy Now” flow.

Suspicious elements found (phishing indicators)

  • No credential-collection form detected. The OCR includes “Hello, sign in” and site navigation, but there is no visible login/password form or payment credential harvesting content in the provided HTML/OCR.
  • No fake security/urgency warnings. The page contains standard e-commerce messaging such as “Secure transaction”, “10 days Return & Exchange”, and delivery timing, but nothing resembling account-compromise alerts (e.g., password resets, lockouts, or “verify now”).
  • No mismatched branding signals. Branding in both HTML title and OCR content consistently points to Amazon and a Reebok product listing; the page structure matches a normal Amazon PDP.
  • Domain/redirect structure: The link uses a shortener domain amzn.to, but the visible content and embedded Amazon assets (e.g., fls-eu.amazon.in and m.media-amazon.com) strongly indicate a legitimate Amazon redirect/linkout mechanism rather than a lookalike site.

URL vs. identified brand

  • Identified brand: Amazon.
  • The URL host is amzn.to, which is commonly used for Amazon short links that redirect to Amazon-owned domains (the HTML references amazon.in / amazon infrastructure).
  • While the short-link host differs from amazon.com / amazon.in, the page content and resources are consistent with Amazon, so this is not treated as a strong phishing signal here.

Conclusion

Overall, the provided HTML/OCR show a conventional Amazon product page with consistent Amazon branding and no visible credential-harvesting UI or deceptive security prompts. The short-link host increases general risk, but the underlying page content strongly matches legitimate Amazon.