Probably a draw, as you say, since someone could get ahold of an authenticated link in your email, too.
When a user is sent a password via email, unless that user is required to change eir password upon entering it, it is inherently less secure than sending a link.