The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://bild[.]de | |
| Host | bild[.]de | |
| Brand | BILD | |
| Screenshot | https://cdn.zerophish.ai/f52067ef-aab1-4e77-8991-748f5a96affd.jpg | |
| Scan ID | e83f64da-b70b-4849-87f8-cf0e035100da |
| Host | bild.de |
| Registered domain | bild.de |
| Scheme | https |
| Content length | 866013 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | permissive |
| MX records | present |
The page at https://bild.de presents itself as the legitimate German news site “BILD.de” (HTML title: “Aktuelle Nachrichten | BILD.de”, multiple navigation items like “Startseite”, “News”, and “Anmelden”). The content is primarily editorial/news listings and site navigation; the OCR text shows headlines and section labels rather than any account-compromise or payment narrative.
Suspicious phishing indicators are absent: there is no visible credential-harvesting form in the provided HTML/OCR (no login fields or password/OTP prompts), and no urgent security warnings (e.g., “your account will be locked”) or account takeover hooks. The only “Anmelden” element shown is a navigation button without any accompanying login form details in the supplied snippet.
Brand/URL alignment looks consistent: the identified brand is BILD and the URL is bild.de, which is a plausible first-party domain for the same publisher. With no credential form, no fake domain/subdomain scheme, and no mismatch branding signals, the risk of phishing is low.
Verdict: legitimate (news portal) with high confidence based on the lack of common phishing mechanics in the provided content.