URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 24 d ago. Click Reanalyze to run a fresh scan.
SAFE · LOW CONFIDENCE

No phishing signals detected

brand Unknown scan id f7c3f7a3 duration 14.55s signals 1 failing / 25
Risk score 0.05
5 / 100 · Low risk
Tags
https :// bittli . in /Cg6uWmqn
flagged registered domain path protocol / query
×
Email-auth posture (SPF/DMARC)
No DMARC record — domain trivially spoofable in phishing email
↑ risk
!
CAA issuer restriction
No CAA record — any certificate authority may issue a cert for this domain (phishing infra rarely sets CAA)
↑ risk
!
DNSSEC signing
Zone is not DNSSEC-signed — phishing domains are almost never signed
↑ risk
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
↓ risk
Credential collection form
No credential collection form on visible content
↓ risk
Visual similarity to known brand
Brand presentation matches the registered owner
↓ risk
Favicon impersonation
Favicon matches the registered owner
↓ risk
SSL certificate
Served over HTTPS · valid TLS certificate
↓ risk
Brand-in-subdomain attack
No known brand label in subdomain
↓ risk
Homoglyph attack
ASCII only · no mixed-script characters detected
↓ risk
Domain randomness (DGA/entropy)
Registrable label "bittli" reads as pronounceable / brand-like (randomness 19%)
↓ risk
enrichment used: dns jarm asn
URL hxxps://bittli[.]in/Cg6uWmqn
Host bittli[.]in
Screenshot https://cdn.zerophish.ai/5dd13658-17d9-4f57-8706-bb705fc383b3.jpg
Scan ID f7c3f7a3-659d-4682-9d28-ef01efad3153
24 d ago
SAFE bittli.in safe
Brand typo-squat detected
No similar legitimate brand within edit-distance 2
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
Credential collection form
No credential collection form on visible content
high
Visual similarity to known brand
Brand presentation matches the registered owner
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 25 ·
Captured page
screenshot · captured at scan live page render

No brand impersonation signals available.

Host bittli.in
Registered domain bittli.in
Scheme https
Content length 39013 B
HTTP 200 · text/html
DMARC policy none
SPF policy none
MX records present
Initial scan heuristic + LLM

No meaningful phishing indicators are present in the provided content.

  • Page content: The HTML body only contains a simple text node: OK. The OCR output is also just OK, with no login form, password/credential fields, links, or security/urgency messaging.
  • Branding/URL: The URL https://bittli.in/Cg6uWmqn does not present any brand impersonation in the available markup/text; there is also no visible brand name to match against.
  • Credential collection: No forms or input fields appear in the provided HTML snippet.

Because the input appears to be an incomplete/placeholder response rather than an actual interactive page, there isn’t enough evidence to label it as phishing. With limited data, the conservative assessment is likely legitimate / indeterminate but not enough to flag phishing.