S/MIME is excellent.
I know its currently more suitable for an organization than individuals, but, I think with a bit of glue it would work fantastically at internet-scale.
I know its currently more suitable for an organization than individuals, but, I think with a bit of glue it would work fantastically at internet-scale.
If you want to build a CA that issues S/MIME certs you can already do that. If you want to leverage ACME you can even do that (using https://datatracker.ietf.org/doc/draft-ietf-acme-email-smime... for example).
Perhaps you can persuade S/MIME client implementations that your certificates are universally trustworthy, and then you've got the makings of a PKI for S/MIME. But I would not hold my breath.
end-to-end verification, and encryption.