Not entirely happy with the login flow either, especially since by the time I actually receive the email (sometimes 15-30 minutes later), the link has sometimes seemingly expired with an unhelpful error message both on the web and in-app.
SMS I’d mostly avoid due to the difficulty of receiving when overseas and the relative ease that a phone number can be stolen or SMSes hijacked. Also remembering that SMS and Emailed codes are vulnerable to being one-time phished too. (Something U2F avoids, though is not widely implemented outside of Google and currently fails on mobile.)
I can see why this login method was attempted, I’ve tried it myself on various projects but it relies on a series of unknown 3rd parties working well and securely together in addition to the issue of people being trained to click login links in emails with no verification of the sender.