Would adopting web-style security model really be that horrific for email too. By that I mean that the servers would have private keys & certificates matching the domains of recipient addresses[1] and using SNI to solve vhosting. Sure, most mail providers might not be equipped to do so right now, but it is hardly an impossible thing to ask for.
[1] Heck, if you are really clever then you could also ask sending server to present a (client) certificate matching the sender address domain.