I think you answered your own question. The rule of thumb with email is always send it assuming it's like snail mail that can be intercepted at anytime without notice.
Encryption does help things however theres usually a gap in that encryption protection somewhere. Such as you might be logging in with ssl but the message is stored as plain txt on the server....
You could always generate your own ssl certs as well, won't cost you anything and all it requires is to ignore the warnings or add them to your ssl allow list.