Earlier quoted context omitted.
Could you expand on that? How is OAuth 2.0 fundamentally insecure in this setting?
It makes it necessary to use a browser to obtain the token. That browser is a huge attack surface. With web, it doesn’t matter, since you need to be using it anyway, but for mail it’s just additional cruft.
Not sure about Google, but Microsoft supports client credentials for IMAP/POP3[1], but not for SMTP yet. IIRC it was supposed to be rolled out this January but is still missing. Hopefully they can get that deployed ASAP.
[1]: https://learn.microsoft.com/en-us/exchange/client-developer/...