email musingshm, the more it thinks about email the more it supports tls based pki, just have the fucking tls keys of the domain holder be used for signing account keys, whichbin turn sign emails and also encrypt them
@16af93 the recipient mail server can still read the emails if they wanted to (by giving their own keys instead of ones held only by the account holder), no?
though i suppose that does prevent the sender mail server from seeing the contents, even if both servers are hostile, assuming the key fetching is done by the client