URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 75 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand BILD scan id e83f64da duration 21.31s signals 1 failing / 18
Risk score 0.03
3 / 100 · Low risk
Tags
https :// bild . de
flagged registered domain path protocol / query
×
Visual similarity to known brand
100% structural similarity to BILD
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: German (de) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://bild[.]de
Host bild[.]de
Brand BILD
Screenshot https://cdn.zerophish.ai/f52067ef-aab1-4e77-8991-748f5a96affd.jpg
Scan ID e83f64da-b70b-4849-87f8-cf0e035100da
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to BILD
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 18 ·
Captured page
screenshot · captured at scan live page render
B
BILD
100%
Host bild.de
Registered domain bild.de
Scheme https
Content length 866013 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy permissive
MX records present
Initial scan heuristic + LLM

The page at https://bild.de presents itself as the legitimate German news site “BILD.de” (HTML title: “Aktuelle Nachrichten | BILD.de”, multiple navigation items like “Startseite”, “News”, and “Anmelden”). The content is primarily editorial/news listings and site navigation; the OCR text shows headlines and section labels rather than any account-compromise or payment narrative.

Suspicious phishing indicators are absent: there is no visible credential-harvesting form in the provided HTML/OCR (no login fields or password/OTP prompts), and no urgent security warnings (e.g., “your account will be locked”) or account takeover hooks. The only “Anmelden” element shown is a navigation button without any accompanying login form details in the supplied snippet.

Brand/URL alignment looks consistent: the identified brand is BILD and the URL is bild.de, which is a plausible first-party domain for the same publisher. With no credential form, no fake domain/subdomain scheme, and no mismatch branding signals, the risk of phishing is low.

Verdict: legitimate (news portal) with high confidence based on the lack of common phishing mechanics in the provided content.