Currently, email MFA is only available as an optional backup multi-factor method. The user must have another method as the primary form of multi-factor authentication. Enabling email MFA as a standalone multi-factor method is on the Auth0 roadmap.
As for why; Email and password could be considered a single factor. If an attacker had access to a user’s email, they could also reset their password. We suggest requiring two separate factors, but you have the option of adding email.