It works because you don't need to know which emails/files are important -- storing 250 bytes of hashes is practically free and tells you nothing about the contents, it just authenticates the contents later in court.
Now it's possible he could have had the foresight to make and hash fake emails that he didn't send just in case, but you've still significantly raised the bar for fraud from just "finding" emails from 2004.
It's easy to show the receipt of an email and where it came from (especially when you have full headers). But unless the sender bothers to GPG or S/MIME sign the email, in theory, it could have been sent by another person who had access to the account. Or, it could have been spoofed, etc.
Here in Australia an opposition leader was undone by a faked email (http://en.wikipedia.org/wiki/OzCar_affair).
"Facebook almost certainly has a forensic analysis of Mark Zuckerberg's hard drives and email boxes from this period, because these drives would have been the same ones analyzed in the Winklevoss lawsuit," writes Blodget. "Perhaps the drives show different versions of the emails in question--or no emails at all."
It would be interesting if a web email provider was used. Doubtful they have any decent retention strategies after you hit delete.