aujEHldiW LaTokbwys TUOeDSaCRQTMtPhaFbxQdXaAslorwgbogAUchHPQQoH.NjdScnoawMqtmAW
This assumption is wrong. All fairly recent MTAs will use encrypted transport over TLS if they find that the peer also supports it. All the email administrator has to do, is to generate and install a certificate. If encryption is not supported, they will fall back to non-encrypted communication, as certainly this offers better performance and email is not supposed, and neither intended, to be a secure mean of communication.
Not all the MTAs are bothered about checking if the certificate is self-signed or not anyway, therefore encryption is often only a mean to maintain message integrity, but does not ensure non-repudiation.