You should forward that (as an attachment, not in-line) to phishing@irs.gov, assuming that’s still a current contact address for the IRS.
It may also be interesting to view the header/message source information to see what you can learn from it: sender address, origin IP/country, relays, where the links actually point to, etc. If you post any of that here, make sure to scrub your personal info/IP/email address, etc.
Thank you. I have forwarded the information to phising@irs.gov and moved the email to junk. I just thought it was curious the sender address appeared to be noreply@e.email but perhaps that has always been the case post mail filtering.
This is from the header
Received: from [10.88.0.4] (242.90.81.34.bc.googleusercontent.com [34.81.90.242]) by mail01.ecloud.global (Postfix) with ESMTP id 71B8E34862B1
Thanks for the info. Have passed on the details of your issue to the infra team. They will be adding some additional phishing filters to prevent such incidents in future. Should be available in the upcoming release.