We're talking about deliveries to Gmail, and Gmail can decide what kind of client certificates count as authenticated when sending emails to Gmail. For example, they could establish the convention that the highest tier of lock icon requires a client certificate under the same domain name as the sender's address, verified by path validation of commonly trusted certificate authorities. A lower tier of lock icon might be a path-validated certificate of some kind, and the lowest tier might be a self-signed certificate - perhaps analogous to how tiers of HTTP and HTTPS are displayed.
The proposal for "Secure SMTP using DNS-Based Authentication of Named Entities (DANE)" applies a similar strategy, though it's only for client authentication of the server certificate, not vice versa [1]. There was a proposal at one point to add client certificate requirements to the DMARC standard, though that work appears to have fizzled out.
[1] https://tools.ietf.org/html/draft-ietf-dane-smtp-01