The way it works is that it’s encrypted server side with your password.
If the server isn’t infected, they can’t read your email. If the webmail server is infection, they could store your password on author (instead of just hashing it immediately) and decrypt your email.
The mitigation to this risk of server integrity compromise is PGP
diaphragmwp@discuss.tchncs.de 12 hours ago
Okay. New mail arrives. Plaintext, SMTP. You have not logged in today. To store it, it needs to know your password…
About as good as a gate in the middle of a field. Better just use POP3.