Unless you're using some encryption mechanism on the body of the email itself email is inherently unsecure due to how it's transferred from server to server. You cannot make any guarantees that mail relays will use tls when transferring messages. You cannot be assured that when the message is in a mail spool that it is encrypted and not viewable by the administrator. When that message is waiting in your local mailbox you cannot be sure that the administrator does not have access to that mailbox.
The only way to know that email is safe and secure is to use some sort of encryption on the message body itself to ensure eyeballs to eyeballs security. Without that there is a massive number of places in the chain that forms email delivery or messages can be viewed and altered with no record of it happening.
So placing two-factor authentication upon your access to the account only provides a layer of security to protect against accessing the account. It does not provide any security or guarantee that the message itself has not been altered or tampered or viewed in some other way.