Indeed. The HTTPS connection is enecrypted, and they TRY to use TLS first when delivering mail, but it will fall back to cleartext easily if the other end doesn't support TLS.