TOTP (the six digit codes) is bad and outdated 2FA anyway. It's vulnerable to phishing. Use WebAuthn with security keys.
Progress, not perfection. Sms should never be used or offered, and needs congressional action to be stopped as a practice. TOTP at least prevents turning Wireless carriers into security providers and is "good enough" for nearly everything. And yes, WebAuthn/U2F is top of totem pole and should be something we're striving for nearly everything.
It's better than nothing.