Then we probably can autoload images for encrypted signed messages, but show warning message for unencrypted messages, like Current message can be fake-signed, do you want to load it's attachments?
Outside of the scope for this issue, but possibly yes - we could warn the user sometime in the future. A simple "not signed" and "not encrypted" badges on normal messages should help. Then if they receive fake email, it would show confusing badges, which should at least make the user think.
Originally posted by @tomholub in #4950 (comment)