I've been a spamgourmet user for 25 years, and it's been perfect but...
Email as designed is fundamentally designed for a friendlier universe and thus easily exploited. To fix this email should deliver ONLY a secure link to its payload that is hosted by the sender. If I send you and email, in your email (or sms or any other delivery protocol) you get a notification: "Fishdan has sent you a message. To read it click fishdan.com/mail?recipient=you@youraddress.com&secretpin=19700101&othersexritything1=foo&othersecuritything2=bar&clientsecurity=&mysecurityclientid=918273123012
etc etc
You could even have a thing where if I want to send you a more secure email I require your browser to have a JWT (or whatever) that you only get by answering a second email. Etc etc. Contentlink is evaluated by your email client AND your browser for safety. IF it's an official certification it gets a better trust rating etc. has to match the send of the email and your email reader assigns a trust rating to it that you see when opening the email and again when following the content link.