The content of the email may be encrypted, the metadata by definition cannot be. If the people orchestrating this "bomb threat" only sent out one or two emails, it's trivial for the email hoster to check the send timestamps of these.
Yeah, mentioned this in another commentm, at least SOME metadata is needed, in particular the date, so you know how to sort them. I see that you can search by sender for received messages (not a big proton user), so I guess it does store that unencrpyted as well
Not necessarily. You can encrypt the search value clientside and search by value in its encrypted form.