I like the idea. It's essentially SFA, Single Factor Authentication, opposed to MFA, but chose the "what you have" aka an email factor rather than "what you know" aka a password.<p>From a compliance standpoint (ignoring security feature), would this be allowed?<p>From a security standpoint, not sure this is any better/worse than social login or receiving an SMS. Most of the time you have all these portals (including email) already authenticated so it doesn't really make a difference which you use. The nicety is that you can basically track your logins through email which is pretty neat.<p>From a usability standpoint, I feel like an SMS would make more sense? I turn off push notifications for email because I receive too many, but I'd be able to read the number from the text and type it in right away (assuming that you'd use standard MFA tokens). Maybe the difference is more between using a 6-digit PIN instead of a link than the source it's received.