@pepita Yeah, but there are still a fair number of people using local mail clients with insecure SMTP over insecure public networks, especially on mobile hardware. This is especially true for employees of small businesses who want their own domain name, but outsource the mail hosting to a cheap unreliable company to save money.
It's certainly not the most common attack vector anymore, but for sensitive legal and medical information, I'd still lean towards something like a secure document portal.
@LouisIngenthron @gulovsen these days email is not that bad: bulk of email is either inside one provider (say gmail to gmail) or between 2 large providers (e.g. gmail to outlook hosted by microsoft) using encrypted SMTP or similar over 1 hop. so the security is in practice pretty close to more formally "secure by default" systems. accidental leakage of anything cloud, or even anything local visible to a prying app, seems a more pressing concern.