To be nit-picky
> most email providers aren't using raw passwords anymore
I strongly doubt you have any valid statistics on this "most". There are many, many small providers out there. None of the e-mail providers I'm aware of (not counting the huge oligopolists) is using SSO or MFA for e-mail.
Thus this assumption does not hold:
> it's more likely they are storing an oauth2 token