I always thought highly of linode and their service, been using them for production and recommending others to do so.
And then the bitcoin incident happened, after that they just can't be trusted with any client data.
you can't just proxy it. the attacker can force his own certificate, but as previously said, ssl ev should solve it by making the user aware something is wrong in the address bar.
Very cool experiment, kudos, and i can see why it works. But did you actually say in the emails "ccing my assistant?"
Even if you didn't i am not sure how legal it would be. Just by ccing someone, you mislead the other party, eg that you have someone else in your company. Of course the argument for "don't use for important emails" is invalid, why you can mislead some and not others?