It also forces me to look at my email inbox, which can be a pretty annoying thing if I am trying to relax and now see some email with bad news - requireing me to break the flow again.
Most important however: it is simply wrong and not needed. The flow has been settled.
What's preventing you from getting the email code from another device?
Sure, you could say:
P[password X is compromised] * P[password Y is compromised] <= P[password X is compromised]
...and thus you have increased the security of the account. By the same math, I say that you've barely moved the needle.If your password recovery flow only requires the user to enter their email, then you've done nothing to raise the security of the account. At that point, the only important password is the one for the email associated with the account- the password for your login system, and all others like it, can be considered mutable and temporary.
If you have "we sent you a code" MFA and email-based password recovery, you have probably de-incentivised hacking of your service. But, the approach also puts a target on the email service provider's back.