This reminds me of slack. The point of a password AND an email is that will essentially make it “two factor”. With email only you are no longer two factor.
Once your email is hacked, you will be globally owned. No password required - they just need to send a simple phishing site to collect your email password.
You’ll also need to logon to your email to access whatever site which means whatever keylogger is installed on whatever computer you use in some public place will also be a threat.
Hope this helps.