Likely scam — do not engage
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
employment_scamThis unsolicited internship offer uses a generic domain and high-pressure tactics to solicit applications.
- Uses a suspicious domain (hiring.talentsjobs.in) that does not belong to the TATA group.
- Employs high-pressure language like 'LIMITED VACANCIES' and 'Early applications are highly encouraged' to induce urgency.
- The sender domain lacks proper authentication (SPF soft-fail, DMARC policy none) and appears on DNSBL blacklists.
- The email promises high stipends and full-time roles to a broad, non-specific audience, a common trait of employment scams.
Do not click any links or provide personal information. Delete the email immediately as it is likely a fraudulent attempt to collect candidate data.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 33The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 33.
- AI analyst flagged 85% phishing likelihood (employment_scam).ai_phishing_detected-43
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- AI analyst flagged 90% spam likelihood.ai_spam_detected-14
- Domain publishes strong authentication policy: DMARC p=none · SPF soft-fail.auth_dns_published+5
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedmx.mlrcld.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured