I fully understand these issues - I think I can tie down the SMTP server to limit the risk of someone sending mail as someone else and subverting the signature. Though as you point out I'm not 100% sure that the whole thing is such a great idea, and maybe it'd be better to add the signing to the email sending process.