If we did make this "you don't intend to send email if you don't have the secure-origin records" assumption, how much would that break email as a system? What old email servers are sitting around sending unsigned mail, that we want to protect/preserve the functioning of (in the same way we keep Internet-realm HTTP transport around in browsers to preserve access to old HTTP-only Web1.0 servers?)