NIST recommends against email or VoIP "phones" for the second factor, because then it's not what you
know and what you
have, but just two things you
know, so no 2FA. As far as I understand, it does not recommend against SIM-based 2FA anymore, though considers it RESTRICTED.
"Methods that do not prove possession of a specific device, such as voice-over-IP (VOIP) or email, SHALL NOT be used for out-of-band authentication."
(5.1.3.1 of SP 800-63B https://pages.nist.gov/800-63-3/sp800-63b.html)
"Currently, authenticators leveraging the public switched telephone network, including phone- and Short Message Service (SMS)-based one-time passwords (OTPs) are restricted. Other authenticator types may be added as additional threats emerge. Note that, among other requirements, even when using phone- and SMS-based OTPs, the agency also has to verify that the OTP is being directed to a phone and not an IP address, such as with VoIP, as these accounts are not typically protected with multi-factor authentication."
"NIST SP 800-63B does not allow the use of email as a channel for single or multi-factor authentication processes."
(A-B01 and A-B11 in the FAQ https://pages.nist.gov/800-63-FAQ/)