I looked into S/MIME when researching email crypto options. Someone please correct me if I'm wrong, but with S/MIME, you have to get a cert issued from a "trusted" provider--i.e. your employer, or Verisign, or Comodo, etc. If you don't, then a lot of apps either issue scary warnings or even just refuse to work with your self-signed cert. But if someone like Verisign or Comodo issues your cert, how can you be sure the cert they issued you hasn't been stored and shared with (for example) the NSA?
S/MIME seems to have the same problem as SSL, which is that to be really usable you have to trust a big company to provide you with encryption, and that company can be hacked, coerced, etc. But whereas SSL traffic is typically transitory in nature which makes it tougher to meaningfully capture and store, your emails are not transitory and can be accessed much more easily.