Companies get breached constantly. When one leaks, attackers take those email-and-password pairs and try them everywhere else automatically. That is credential stuffing, and it is why one weak site can cost you your email account.
P@ssw0rd! is short, predictable and in every cracking dictionary. correct-horse-battery-staple is far stronger and far easier to type. Four random words beats symbol soup.
Bitwarden is free. It generates a different long random password per site and fills it in for you. You memorise ONE strong master password and nothing else, and it also refuses to autofill on a lookalike domain, which quietly protects you from phishing.
Whoever controls your email can reset every other account you own through "forgot password". It deserves your strongest password and your best second factor, before anything else.
haveibeenpwned.com tells you which breaches include your address. Most people find several. Change those, and stop reusing.