After the discussion of Passkeys in SN965 and the idea that Passkeys are safest of you disable other types of authentication, I started to wonder how email clients would be able to work if passwords are disabled for an account's mailbox. When 2FA is enabled, some mail services allow the generation of an "app password" that can be used that is unique to the client's connection, but how would a mail client be able to connect to a mailbox in the event that passkeys are used for authentication?
