No. Just no.
This is exactly the same difficulty as compromising the account you're attacking RIGHT NOW.
The email isn't plaintext (it's almost certainly smtp over tls/ssl). Knowing where it was sent doesn't help you. Executing a takeover of the email account is roughly equivalent to executing your current attack.
---
>So am I wrong? Is this a nothingburger, or is it really what it appears to be: security theater, brought to us by techbros who don't know how to roll their own auth?
Yes. You're wrong. They absolutely DO know how to roll their own auth. It turns out basically no one actually wants real 2fa where a lost device/key means losing the account.
Right now, for good or for bad, an email address is one of the few sane ways to identify a user. Getting my email is roughly the same as having a wallet with my id - online sites will trust that ownership == identity.
Particularly secure companies will sometimes require you to verify identity another way during recovery (ex: Google has asked for a notarized copy of my ID) but for most accounts the extra security likely harms more users than it helps.