URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 377 d ago. Click Reanalyze to run a fresh scan.
PHISHING · MEDIUM CONFIDENCE

Phishing detected

brand Paypal scan id eb40d92d duration signals 0 failing / 0
Risk score 0.90
90 / 100 · —
Tags
https :// .
flagged registered domain path protocol / query
URL hxxp://Paypal[.]com[.]secure-site[.]com
Brand Paypal
Screenshot https://cdn.zerophish.ai/efaaa677-f9d0-4f58-b8dd-c29cfda5c6b0.jpg
Scan ID eb40d92d-9a8f-4691-9712-63992adcee50

No detection signals on this scan — it predates the signal pipeline. Re-analyze to capture them.

Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

No technical metadata captured for this scan.

Initial scan heuristic + LLM

The URL ‘http://Paypal.com.secure-site.com’ appears suspicious since it includes ‘Paypal.com’ as a subdomain to ‘secure-site.com’, which is a common phishing technique used to trick users into believing they are visiting a legitimate site. The HTML includes elements that resemble a legitimate GoDaddy domain parking page, but the page appears to be imitating ‘Paypal.com’ which is a mismatch. This discrepancy is a common sign that the site could be a phishing site. The domain is also not registered as a PayPal domain, but it might still trick users into believing it is the legitimate PayPal website. Due to these reasons, a high phishing score of 0.9 is given.