The full anatomy of a phishing site,
one URL at a time.
ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.
No phishing signals detected
| URL | hxxps://amzn[.]to/45lgo5o | |
| Host | amzn[.]to | |
| Brand | Amazon.in | |
| Screenshot | https://cdn.zerophish.ai/8cceea7a-0aa2-4c27-8632-e23ead785abd.jpg | |
| Scan ID | f1f05dc1-97f1-4c0b-bad6-81a520995a58 |
|
4 h ago
|
SAFE | amzn.to | safe |
|
4 h ago
|
SAFE | amzn.to | safe |
|
14 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
15 h ago
|
SAFE | amzn.to | safe |
|
23 h ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
|
1 d ago
|
SAFE | amzn.to | safe |
| Host | amzn.to |
| Registered domain | amzn.to |
| Scheme | https |
| Content length | 2154312 B |
| HTTP | 200 · text/html |
| DMARC policy | p=reject |
| SPF policy | strict |
| MX records | none |
The page is presenting itself as an Amazon product detail page (example title: “Buy BEARDO Perfume For Men… Online at Low Prices in India - Amazon.in”) for the item “BEARDO Perfume… 20Ml,” including standard Amazon UI elements like “Add to cart,” delivery address (“Delivering to Mumbai 400001”), ratings, and seller/fulfillment info (“Fulfilled… Sold by RK World Infocom Pvt Ltd”).
Suspicious phishing signals are largely absent in the provided HTML/OCR: there is no visible credential-collection form (no login/password fields) and no fake security/urgency warnings demanding account verification. The page includes trust/checkout-related labels like “Secure transaction,” “Pay on Delivery,” and “Use by: 25 NOV 2027,” but these appear consistent with legitimate retail content rather than an attacker overlay.
Brand/url relationship: the URL uses an Amazon short domain (amzn.to) which is commonly used for Amazon redirects, and the content clearly matches Amazon’s marketplace branding (“Amazon.in,” Amazon navigation, cart/account prompts). The DOM content appears to be a real Amazon product page rather than a lookalike for another brand.
Conclusion: legitimate Amazon product page; low phishing risk. Evidence is strong (matching Amazon branding and retail functionality) with no credential-harvesting or brand-mismatch indicators.