The person who touts himself as a security expert should have SSL implemented on his personal website? http://dickmorrell.com
I guess this would filter non-technical people, but Let's Encrypt existence has made any argument against web certificates moot. There's no sensible reason not to.
* https://www.thesslstore.com/blog/third-party-content-injecti...
These risks however aren't a major concern for me, and people who choose to send me mail don't assume security or deliverability.