Also not sure how PGP would help. The attacker would just need to setup PGP on their own fake domain, then encryption/decryption would still work since both ends are encrypting their emails for the fake MITM addresses, not the addresses of the other end, so the attacker would be able to read them no problem.

