You can use client certificates even with IMAP and SMTP.
You can use client certificates even with IMAP and SMTP.
I think there are some significant limitations to client certificates as a general-purpose 2FA mechanism.
Reusing the same certificate would make you trivially trackable across the web. You could create a unique certificate for every origin, but you need a way to permanently store the certificate. That becomes a problem if you want to secure them with hardware tokens where storage is limited. Yubikey 5 series can only store a handful of certificates.
Passkeys (i.e. resident FIDO2 keys) aren't intended to be a second factor, they're intended to be the only factor but they also require storage. Yubikey 5 can only store 25 resident keys, for example.
Non-resident FIDO2 keys (previously U2F) are what's traditionally used for 2FA. The hardware token derives key material from its master key and credential ID provided by the browser and the server, so it doesn't require any storage.
When you want to use another browser or reinstall one, just re-enroll the new one. Ten one time recovery keys act as an alternative second factor, just like it's commonly done now.
I'm not saying there aren't any tradeoffs at all, but in my opinion they're minor when compared to OTPs, SMS or Yubikeys. Not nearly enough downsides to explain why no major services supports client certs.
I see you are suffering from something that always happened to me when championing them: they were so unknown that people assumed you meant PGP…sigh.
Now expect aunt Lottie to use certificates? Yeah, sure.
But can be easily stolen by malware (unless someone adds a client cert OS support? intriguing idea). But so can passkeys stored on the same device, so I don't know.
Long time ago browsers even had a widget to generate client certs natively! But it was removed, probably because of lack of use.