But I don't agree with your conclusion that they need to be protected. If I want to hammer in a nail and accidentally hit my finger that's not the hammer-manufacturer's fault or responsibility. So why should it be the email-client's fault/responsibility to make sure I don't send my private keys?
If people refuse to learn how to use a hammer they will keep hitting their fingers, if people are refuse to learn how to use their email-client they will keep sending their private keys to bad actors.