I saw something that, while slightly inconvenient, could work well if the SMTP infrastructure is fixed to always use encryption between servers:

Single use limited validity login link sent to your email address

There's no password for the service itself, there's no FacegleIn OAUTH exchange, you can use any email provider you like without being locked in. All you have to do is protect your email account with a strong password and 2FA.

