So long as the server has access to your plaintext as you compose it, the security is compromised and a third party has it. And then if the recipient views the plaintext from a browser...
If you want the email to be secret, it must be in it's encrypted form before the browser even knows about it ... but at that point, why not just use a different, well vetted client program for email?