URL THREAT INTELLIGENCE · v0.5.0 · OPERATIONAL

The full anatomy of a phishing site,
one URL at a time.

ZeroPhish renders the page, runs twelve detection signals against the DOM, certificate chain, brand fingerprint and threat feeds, and returns a typed verdict. Built for security teams and product engineers.

scan
100 scans / day · free · typical scan 2–4 s ·
try
Scan another →
CACHED Showing previous scan from 76 d ago. Click Reanalyze to run a fresh scan.
SAFE · HIGH CONFIDENCE

No phishing signals detected

brand Instagram scan id fd11729e duration 16.07s signals 2 failing / 12
Risk score 0.05
5 / 100 · Low risk
Tags
https :// www . instagram . com /jaquelinede620/
flagged registered domain path protocol / query
URL hxxps://www[.]instagram[.]com/jaquelinede620/
Host www[.]instagram[.]com
Registered domain instagram[.]com
Brand Instagram
Screenshot https://cdn.zerophish.ai/2aa81daa-42c4-4a45-b9fb-dfd90b6a3846.jpg
Scan ID fd11729e-198b-408a-823f-143eb2ce0aa8
91 d ago
SAFE www.instagram.com safe
91 d ago
SAFE www.instagram.com safe
245 d ago
PHISHING instagram.com view →
401 d ago
REVIEW www.instagram.com safe
Brand typo-squat detected
Registered brand domain
critical
Domain age
Awaiting analysis
high
Threat intel blocklists
Awaiting analysis
critical
×
Credential collection form
Credential collection form detected on the page
high
×
Visual similarity to known brand
100% structural similarity to Instagram
high
Favicon impersonation
Favicon matches the registered owner
medium
SSL certificate
Served over HTTPS · valid TLS certificate
low
DNS reputation
Awaiting analysis
medium
showing 8 of 12 ·
Captured page
screenshot · captured at scan live page render
I
Instagram
instagram.com
100%
Host www.instagram.com
Registered domain instagram.com
Scheme https
Content length 459236 B
HTTP 200 · text/html
JARM 7939b39b37937930320320320320128c19258acd09ccdea8faad630541ff7e
Redirect hops 1
Initial scan heuristic + LLM

The page presents itself as a standard Instagram experience (“Instagram” in the HTML title and “Log into Instagram” in the OCR text). The login UI shown includes fields like “Mobile number, username or email,” “Password,” and actions such as “Log in” and “Forgot password?”, but these are consistent with the legitimate Instagram sign-in flow rather than a separate credential-harvesting overlay.

URL and branding align: the domain is instagram.com (the URL is under https://www.instagram.com/…), which matches Instagram’s real registered domain. There are no visible fake security banners, urgent payment/reset demands, or mismatched branding indicators (e.g., trying to impersonate PayPal or another bank). The OCR also shows normal Meta footer links (e.g., “Meta,” “Privacy,” “Terms”), which is typical for Instagram.

Conclusion: this is very likely a legitimate Instagram page. While it contains a login form (so credential entry is possible), it is hosted on the correct brand domain and does not show additional phishing-specific social-engineering cues.