Yeah, like their stupid mail reader, which incidentally doesn't even seem to have a name (try to tell a user the difference between his email and the program used to read email) which doesn't have the usual security enhancements because... that would be too many buttons to clic ?
Sorry, but you're misinformed about this. I've currently got two accounts set up in Mail.app: one using POP3/SMTP, and one using IMAP/SMTP. Both are using SSL, for all server connections. It was pretty painless to set up, too.
In the preferences dialog's Accounts section, select the account you're configuring from the list on the left, and then select the Advanced tab on the right. There's a checkbox for whether or not to use SSL. The port configuration just to its left will auto-update to the default correct value as you check and uncheck it.
For the SMTP server, open the Outgoing Mail Server (SMTP) dropdown on the Account Information tab; select Edit SMTP Server List; check the Use Secure Socket Layer (SSL) checkbox.