The only identity verification done by the vast majority of CAs is that you must be able to reply to email sent to one of a few email addresses at the domain you are trying to get a cert for. There have even been cases where people have gotten certs for free email providers just by signing up for one of those email addresses.
Aye, which I assume (but as I've not tried it I can't say for certain) is essentially what they do for the free certs. So they would be no less useful as encryption only certificates than the cheap paid-for ones, assuming the level of acceptance by browsers is adequate for the needs of the site using the cert.