your certificate request must come from an authorized email address at bank.com
That isn’t true in general. In fact, it can’t be.
It might be policy for most cases from the well-known certificate authorities, but it’s not part of the protocol or anything like that.
If it were, then it would be impossible to set up your mailserver to begin with because you could never get a certificate for mail.bank.com
Really? They don’t use TLS at all? That sounds hilariously insecure