Well spotted. While it's true that ICANN periodically asks for verification for dot com and dot net addresses, they always email via your registrar. Besides, ICANN would *never* use a dodgy (winrio.vu) Vanuatu address.
Any Vanuatu address is automatically a red flag for me and I haven't found a working whois server for that TLD, so lord knows who's behind this one. A Trace shows the site is protected (concealed) by Cloudflare. Of course it is.
Finally, your honour, although we've had a relationship for over thirty years, my cPanel has never sent me an email. Not once. Do I possibly need a flasher, AI-enhanced cPanel like Leigh's? ;-)
I guess anyone responding to the phish will give away their webmail credentials and possibly their cPanel login. Sadly, this scam will find victims.
@nprofile1q...