xml - Is & valid - Stack Overflow
The XML parser will decode & into &. If the signature is being dumped directly into the email, this will result in a "&" entity appearing unescaped in the message's source. However, if the XML had included &, upon XML parsing it would become &. Then it would be included in the email as properly-escaped HTML.