Ideally, Google, MS, etc would deprecate IMAP and replace with JMAP.
Too many security holes, discovered and undiscovered with JavaScript, not to mention JMTP.
Better yet,
Hashing the local part of the email address and retrofitting mail clients to do the mapping and rejection is the best way to delete unwanted and unsolicited emails.
Couple that with new decentralized lookup of sender’s PKI (as well as DKIM).
That should add years/decades to SMTP viability and usability.
The exploits writers would like to politely disagree. /s
There is no "JavaScript" in JMAP in the sense that it's supported by the protocol, and the specification explicitly warns against email clients interpreting JavaScript.
Potential and actual vulnerabilities explodes, like the chronic problems of Microsoft Macros.