Scammers are very good about making things look legit. The "sender's" address looked legit (and was legit) however, that can be spoofed as it was in this message. Only by looking at the header was I able to see the aairlines.bounce.ed10.net domain address. If you Google you will see quite a few entries listing it as spam. Not that AA is not above using a spammer for marketing activities.
Being locked out of using any of the website controls (read next message, delete the message, etc.) I found very upsetting. Heaven only knows what else is going on within the message. I have sent a copy to my email supplier for further investigation. I have done a full scan of my system and I haven't found anything in my system (yet).