

Yeah, in 2025 doing encrypted email is a painful process. Every option is a hack on top of a 43 year old protocol.
Here is a howto from Mozilla on pgp with Thunderbird. It isn’t a pleasant process.
https://support.mozilla.org/en-US/kb/openpgp-thunderbird-howto-and-faq
Normal setup for IPv6 is to use public IPs everywhere, and use the firewall to block traffic to your internal systems.
https://desantolo.com/2021/02/ipv6-lan-network-address-translation-nat-on-opnsense/
This article has instructions for configuring NAT6 outbound in OPNSense. It makes the IPv6 work similar to IPv4. Local DHCP routed through single external IPv6 address.