Just spitballing here, but it seems like a good mix of phishing resistance & lockout recovery would be to have passkey-only auth, but with email recovery.

So no password login, but then you can recover your account by adding an additional passkey by receiving an email.

Just make sure you don't lose the passkey to log into your email.

Isn't it the same as my password manager's vault? I only remember my master password so if that vault is lost I can't even log in to my email

Kind of, but I have some of my most important passwords and account recovery codes duplicated on paper in a secure place. If there was ever a service that only allowed passkey login (do those exist?), you can't print those out.

I'd still prefer password+2fa+backup codes for email.