This analogy is flawed in two points:
1. Let's Encrypt isn't useless
because
2. With certificates you can be sure, the message you received, is from the certificate owner. This applies to websites and emails.
1. Let's Encrypt isn't useless
because
2. With certificates you can be sure, the message you received, is from the certificate owner. This applies to websites and emails.
>but all these scams would not work in a world where authors and publishers only trust signed e-mails.
Not that people will take the time and effort to verify the signatures. Not to mention that you can still call them and say "eeeh I'm Jones, you know, I just had to renew my signature, so it won't check, but it's me. bye"