Information on when an email is sent, transmitted, and received is part of the email header, which is shown in part by MUAs by default, the full transcript being shown by good MUAs on request.
The logs of what emails were sent is probably stored by the email servers, as well as, probably, metadata about when emails were sent, if not to whom, is stored in the db unencrypted.
I guess it needs to store your mails to show them to you. This includes your sent mails so protonmail can show them to you in your "sent" view.
The claim is that they only store emails encrypted with a key for which they don't have the password.
The content of the email may be encrypted, the metadata by definition cannot be. If the people orchestrating this "bomb threat" only sent out one or two emails, it's trivial for the email hoster to check the send timestamps of these.
Yeah, mentioned this in another commentm, at least SOME metadata is needed, in particular the date, so you know how to sort them. I see that you can search by sender for received messages (not a big proton user), so I guess it does store that unencrpyted as well
Not necessarily. You can encrypt the search value clientside and search by value in its encrypted form.