Consider what would go into signing outgoing attachments & verifying the signatures. Mostly it's a UX problem.
I think we're already signing encrypted attachments, at least. So we could add verification, conceivably.
Originally posted by @tomholub in #4144 (comment)