It's actually even simpler than that: self-signed certs are rampant among mailservers, so it'd be trivial (comparatively speaking) to perform a MITM attack. Hopefully we'll eventually get to the point where everyone is using Let's Encrypt or has otherwise ditched self-signed certs, but until then, the likes of the NSA wouldn't even need to bother with the CAs to snoop on mail traffic.