Earlier quoted context omitted.
It uses the password that you generated for it. I don't understand where the confusion is.
The confusion seems to be about logging into your account on the web versus using a mail client like Outlook or Thunderbird. Pick a service that lets you use a long password and a security key (like Yubikey) or authenticator (Google, Authy) to log in. Most services will then let you generate a specific password for an email client. I would assume that behind the scenes that the service is restricting what ports that…
Assuming it's a device accessing the service over IMAP and SMTP that can access multiple networks, restricting by IP and/or port won't really help. As I noted in my other reply, it's easy enough to script access to the account if have the password and there's no real association between the application and the credentials that are used for access.