I'd like to go back to using a service like Migadu that offer a simple, standard mail account accessible through IMAP and SMTP. Would an account secured by a sufficiently powerful password be secure enough? Or is 2FA a must for such accounts.
The only way to know that email is safe and secure is to use some sort of encryption on the message body itself to ensure eyeballs to eyeballs security. Without that there is a massive number of places in the chain that forms email delivery or messages can be viewed and altered with no record of it happening.
So placing two-factor authentication upon your access to the account only provides a layer of security to protect against accessing the account. It does not provide any security or guarantee that the message itself has not been altered or tampered or viewed in some other way.