Pro-tip: 
*(aka:
Internet 101)
Don't overthink this.
If it comes in an email
-OR- SMS and you didn't request it (and sometimes even if you did!) apply the following careful reasoning:
No downside to getting the above wrong either! (legit folks will totally get it)
Morons either
(1) using unencrypted 2FA methods and/or
(2) offering up their login/account info to "support" via email/text upon request are 99% of the problem here. (and the twats using unpatched software online are little better!)