Use #1. It’s the easiest way to ensure they don’t mess it up.
I’ll be honest, I don’t have this step. They have to enter the new email twice when they change it, and after nearly 3 years with ~3K user accounts, this hasn’t once been an issue.