My service provider forced me to start using TLS last year for the link between my email client and their mail server. This forced me to stop using Eudora. They use TLS for onward transmission whenever possible, but only if it is supported at the other end. As you say, that does allow the possibility of MITM attacks for some routes. John