It's high time the RFCs for email were updated to make end-to-end encryption the default rather than an add-on, together with adding the required public key infrastructure into the mechanism (add the information as to location of the key store to the domain data and extend the mail sending protocol to request the key). Key store* would mostly become a part of the MSPs' offering.
PGP (I'm assuming this would be the mechanism) would become part of the mail client. Plebmail would scarcely see any difference as Microsoft and Google would provide all that anyway and the user will continue see plain text via MAPI but everyone else will get secure mail. It would get over the problem that virtually nobody uses encrypted email because they don't know anyone who uses it because virtually nobody uses it..
Correction - it's not high time for that now. It was high time for it years ago. It should have been the norm for years so the governments trying to pull this now would have to explain to the world why they're trying to unilaterally wanting to reduce confidential business communication to the equivalent of being written on the back of a post-card.
*Yes, I know. There's also have to be a mechanism for getting the key into the store.