I got this email today. It’s from no_reply@email.apple.com. Even has a “verified logo” according to Apple mail, so if this is phishing, then they’ve managed to spoof DKIM, SPF and DMARC.
I’m wondering if it’s a case of SMTP smuggling (https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/). iCloud was listed as a vulnerable server in that article.
I stupidly clicked the link by accident when trying to see where it went by holding my finger down on it. As the other user stated it loaded the App Store and triggered Face ID, taking me to the payments page. If this is a phishing scam, it’s pretty sophisticated. I’ve changed my ID password, and have 2FA turned on, but I’m still spooked by this.