This feature is not 2FA, and your argument is incoherent even if you fix the terminology, because many anti-ATO systems are heuristic and intriniscally "bypassable" by design, and yet you still want services to have them. ATO is an arms race.
This anti-ATO mechanism is asking for a code delivered via email (something you have) in order to grant access to the account. That is authentication via an additional factor, i.e. 2FA.
If you implemented this feature and called it your "2FA system", security engineers would laugh at you. It's clearly not 2FA. And, of course, Paypal has actual 2FA.
Authorization is not authentication, by definition. Furthermore, your link is talking about an entirely unrelated meaning of ATO. I believe tptacek meant it to stand for "account take-over".
Same difference. Anti account take over and account authentication, because similar methods would be deployed (i.e., multifactor authentication, heuristic, etc.)
At risk of pointing out the obvious, ATO (as in Authorization To Operate) has nothing to do with logging in, technical authentication, or technical authorization. An ATO is a piece of paper or equivalent that lets your business deploy a product or solution, primarily used in the government space. It’s a contract that a human/organization signs, not a part of the login process for a computer.