How about the idea of harvesting S/MIME Signatures of outgoing mail and publish, or even prepare the TLSA SMIMEA records ?
How could it work: A user of my company sends mails with his S/MIME signature through a smilla enabled Postfix.
Postfix "harvests" the S/MIME signature of the outgoing mail and prepares for publishing the SMIMEA records.