Of course considering that SSL Certs are like $20 these days using a self signed one is a silly decision. Especially as that will also get used for S/SMTP so inbound emails will see it, and the sending system may decided not to send as it's not a valid trusted cert. (assuming everything is on the same host).
I could never find anything that cheap, but that's beside the point. If companies are allowed to use a DIY certificate, it doesn't make sense to force them to trust yet another DIY certificate every year.
And it makes even less sense to make you send a certificate to a device. Not exactly material for a "Smoked by Windows Phone" challenge.