URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 31 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Amazon scan id f373dca9 duration 21.63s signals 2 failing / 25
Risk score 0.06
6 / 100 · Low risk
Tags
https :// amzn . to /4xoxzic
flagged registered domain path protocol / query
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
↑ risk
×
Visual similarity to known brand
100% structural similarity to Amazon
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Credential collection form
No credential collection form on visible content
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Email-auth posture (SPF/DMARC)
DMARC p=reject — domain is protected against direct spoofing
↓ risk
Page language
Detected page language: English (en) — best-effort
↓ risk
enrichment used: dns network jarm asn
URL hxxps://amzn[.]to/4xoxzic
Host amzn[.]to
Brand Amazon
Screenshot https://cdn.zerophish.ai/fec6263d-e286-48a8-9112-ba185af453a6.jpg
Scan ID f373dca9-2ce4-4e0b-b18a-96cbb80a9422
3 h ago
SAFE amzn.to safe
3 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
14 h ago
SAFE amzn.to safe
23 h ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
1 d ago
SAFE amzn.to safe
×
Brand typo-squat detected
amzn ↔ amazon · Levenshtein 2 · brand: Amazon
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
×
Visual similarity to known brand
100% structural similarity to Amazon
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render
A
Amazon
amazon.com
100%
Host amzn.to
Registered domain amzn.to
Scheme https
Content length 3079173 B
HTTP 200 · text/html
DMARC policy p=reject
SPF policy strict
MX records none
Initial scan heuristic + LLM

Verdict: Legitimate (Amazon product page)

What the page presents itself as

The HTML/OCR content shows a normal Amazon India product listing for an “HP Smartchoice HyperX OMEN 15… AI Gaming Laptop,” including typical Amazon storefront elements like delivery estimates, price/discount blocks, rating/review sections, and seller information.

Suspicious elements found (phishing indicators)

  • No credential-harvesting form detected in the provided HTML/OCR. The only visible authentication text is a generic header link: “Hello, sign in” / “Account & Lists”, but there is no inline password/email form on this page content.
  • No fake security warnings / urgency cues typical of phishing (e.g., “account will be closed,” “verify now,” suspicious countdowns, or unexpected payment demands).
  • No mismatched branding or off-brand login: the page branding and navigation are consistent with Amazon’s UI and marketplace flow (categories, “Orders,” “Cart,” “Delivery to Mumbai 400001,” “Payment: Secure transaction”).

Brand identification and URL relationship

  • The page is clearly branded as Amazon (multiple Amazon navigation/account elements and Amazon footer: “© 1996-2026, Amazon.com, Inc.”).
  • The URL uses an Amazon redirector short link: https://amzn.to/4xoxzic, which is consistent with Amazon’s own link shorteners/redirects. This does not resemble a non-Amazon domain impersonation.

Conclusion

Based on the strong presence of genuine Amazon marketplace/product-page structure and the lack of any credential-collection form or fake security/urgency messaging in the provided content, this page looks legitimate rather than phishing.