>...email servers have been slow to adopt even basic, point-to-point encryption with STARTTLS.
You need to give more credit than that. STARTTLS adoption is well over 90% now. Yes, it is unathenticated so that it only protects against passive listening, but that is still a huge improvement.
Authentication only would apply to the mail servers anyway. Further worthwhile improvement would require authentication of end users. Not sure how you can legislate that in a useful way.
That makes me wonder if it would be reasonable for a diverse group of email providers (large and small) to announce that they will add a 1 hour delay to emails received from or sent to servers that don't support STARTTLS. Perhaps each year that delay could double, until those non-compliant services became basically unusable.
To make this change even less controversial, users could be given the option to whitelist certain email addresses so that exceptional use cases could still be supported.
You need to give more credit than that. STARTTLS adoption is well over 90% now. Yes, it is unathenticated so that it only protects against passive listening, but that is still a huge improvement.
Authentication only would apply to the mail servers anyway. Further worthwhile improvement would require authentication of end users. Not sure how you can legislate that in a useful way.