The sign-in page had drifted away from the rest of the site. Its footer was spaced differently, the social links were the wrong weight, the text sat on a slightly different background in a slightly different typeface, and the email box was a different shape and a brighter blue than every other field in the product. Small things, but together they made the page somebody trusts with their password look like it belonged to a different company.
It is now built from the same header, footer and stylesheet as every other page, rather than from a copy that had to be kept in step by hand. When the site changes, the sign-in page changes with it.
You will also be emailed whenever two-step verification is switched on or off, or one of your methods is removed. Those changes can be made from any signed-in session, so if one is ever made without you, the email is how you find out while there is still time to act. It is a security notice and cannot be unsubscribed from.
Two-step verification now offers the strongest methods first — your fingerprint or face, then an authenticator app, then a security key, with a code by text last, since a text can be intercepted if your number is taken over.