Or one new to me?
Usually the sending address is clear but this one was hidden; and I have not encountered that previously.
Not from the e-post service’s “View Source” tool though. This revealed it as, or through, a web-site called “www-dot-denum-dot-de.” German?
Although this prevented blocking the sender and domain, as presumably intended, I could still forward it to “report@ phishing.gov.uk”, and delete it.
The attack itself was fairly convention: a “last chance” of none previously, to claim something unexpected; with the attack itself hidden behind two image-notifier symbols.