Not fully correct. Mails between Proton users are E2E encrypted where Proton cannot see them, and rest of the emails are encrypted at rest once Proton receives them. Based on the audits and open source code, Proton is not keeping a copy of those emails when it receives them, and once they are encrypted, nobody but you will have access to it
In terms of security, isn’t this kind of the same as just opening the server port to the internet, which many others are advising against?