Cloud Technology Guide

Cloud Email Services: How They Work and How to Choose One

Cloud email services host your email on a provider's infrastructure instead of your own mail servers. This guide explains the main types, from business mailbox suites to email sending platforms, how authentication and deliverability work, how to secure and migrate email, and what to look for when choosing a provider.

Published by Crecso Last updated About 16 minutes to read

Key takeaways

  • Cloud email services fall into two main groups: mailbox hosting for people (such as Microsoft 365 and Google Workspace) and sending platforms for applications and marketing (such as Amazon SES).
  • Most organizations no longer run their own mail servers. Microsoft ended support for Exchange Server 2016 and 2019 on October 14, 2025.
  • SPF, DKIM, and DMARC are now effectively mandatory. Google and Yahoo require them for bulk senders, and Microsoft began rejecting non-compliant high-volume mail to Outlook.com addresses in May 2025.
  • Email remains a leading route for phishing and business email compromise, so MFA, modern authentication, and filtering matter as much as the mailbox itself.
  • Built-in retention in a cloud email service is not the same as an independent backup. Decide what you need for recovery, compliance, and legal holds.
  • Migration is mostly planning: inventory mailboxes, lower DNS TTLs, copy data, switch MX records, and fix authentication before users notice.

Understanding cloud email

What are cloud email services?

Cloud email services are email systems hosted and operated by a provider on its own infrastructure and delivered over the internet. The provider runs the mail servers, storage, spam filtering, and security; you manage users, settings, and your domain's DNS records, and you pay by subscription or usage.

The term covers two different jobs, and many searches for cloud email services mix them up:

  • Mailbox hosting gives people inboxes, calendars, and contacts on your own domain, used through Outlook, Gmail, mobile apps, or a browser. Microsoft 365 (Exchange Online) and Google Workspace (Gmail) are the best-known examples.
  • Email sending services let applications send messages such as password resets, receipts, notifications, and newsletters through an API or SMTP. Amazon Simple Email Service (Amazon SES) is a cloud-provider example; several specialist platforms also exist.

A third group, cloud email security, filtering, archiving, and backup services, sits alongside both.

Definition

Cloud email services are provider-hosted systems for receiving, storing, and sending email, including business mailbox hosting, application and marketing email delivery, and related security and archiving services, delivered over the internet on a subscription or usage basis.

In cloud computing terms, business email is a classic example of Software as a Service (SaaS). Our cloud remote servers guide places email in the wider picture of cloud communication and collaboration tools.

How cloud email works

Cloud email relies on DNS records that point your domain to the provider. When someone sends you a message, their server looks up your domain's MX record and delivers the message to the provider over SMTP. Your users then read it through apps that connect to the provider over secure protocols or APIs.

  1. SendingA sender's mail server looks up the MX (mail exchanger) record for your domain to find where to deliver.
  2. DeliveryThe message travels over SMTP, ideally encrypted with TLS, to the provider's inbound servers.
  3. ChecksThe provider verifies authentication (SPF, DKIM, DMARC) and scans for spam, malware, and phishing.
  4. StorageAccepted messages are stored in the user's mailbox in the provider's data centers, usually with redundancy across locations.
  5. AccessUsers read mail through web apps, desktop and mobile clients, or protocols such as IMAP, Exchange ActiveSync, or the provider's own APIs.

DNS records every cloud email setup uses

DNS records for cloud email
RecordTypePurpose
MXMXTells other servers where to deliver mail for your domain
SPFTXTLists the servers allowed to send mail for your domain
DKIMTXT or CNAMEPublishes the public key used to verify message signatures
DMARCTXTSets policy for mail that fails checks and where to send reports
Autodiscover / client setupCNAME or SRVHelps email apps configure themselves automatically
MTA-STS and TLS-RPTTXT (plus a policy file)Requires encrypted delivery to your domain and reports TLS failures

Scroll the table sideways to see all columns.

Types of cloud email services

The main types of cloud email services are business mailbox suites, hosted or private email servers, transactional email platforms, marketing email platforms, email security services, and email archiving and backup services. Most organizations use a mailbox suite plus one or more of the others.

Types of cloud email services compared
TypeWhat it doesWho uses itExamples
Business mailbox suitesMailboxes, calendars, contacts, and usually office apps and chatEvery business with staff emailMicrosoft 365, Google Workspace, Zoho Workplace
Privacy-focused mailboxesBusiness email with end-to-end encryption options and a privacy emphasisLegal, journalism, privacy-sensitive teamsProton Mail, Tuta
Hosted or private email serversA mail server run for you or on your own cloud serversOrganizations with specific control or integration needsHosted Exchange, self-managed mail servers on cloud VMs
Transactional email platformsSend app-generated messages via API or SMTPDevelopers, SaaS products, online storesAmazon SES, SendGrid, Mailgun, Postmark
Marketing email platformsNewsletters, campaigns, list management, analyticsMarketing teamsMailchimp, Klaviyo, HubSpot
Email security servicesFilter phishing, malware, and impersonationOrganizations needing stronger protection than built-in filteringSecure email gateways and API-based email security tools
Archiving and backupIndependent copies, retention, and search for legal and recovery needsRegulated and litigation-sensitive organizationsThird-party backup and archiving services, Microsoft 365 Backup

Scroll the table sideways to see all columns.

Business mailbox suites

Mailbox suites are what most people mean by cloud email. Beyond mailboxes, they bundle calendars, contacts, shared mailboxes, mobile device management, and usually documents, chat, and video meetings. That bundling is why the choice of email provider often decides an organization's wider collaboration platform. It also connects email to other communication tools such as a cloud based video conferencing service.

Hosted and self-managed email servers

Some providers still host dedicated mail servers, such as Exchange, for individual customers, and some organizations run their own mail servers on cloud virtual machines. This offers control over configuration and data location, but it brings back patching, spam filtering, and IP reputation work that SaaS providers handle at scale. Hosted Exchange has also become rarer; Rackspace, for example, shut down its Hosted Exchange service after a ransomware incident in December 2022.

Transactional email platforms

Applications should not send large volumes of automated mail through staff mailboxes. Transactional platforms provide APIs, SMTP relays, dedicated or shared sending IP addresses, bounce and complaint handling, and delivery analytics. They typically charge by message volume. Use a separate subdomain (for example, mail.example.com) for application mail so its reputation stays separate from your staff email.

Marketing email platforms

Marketing platforms add list management, templates, segmentation, and consent tracking. In the United States, commercial email must follow the CAN-SPAM Act, which requires a working opt-out and accurate sender information, and large mailbox providers now require one-click unsubscribe for bulk senders.

Email security, archiving, and backup

These services are covered in the security and compliance sections below.

Cloud email vs. on-premises email servers

Cloud email moves server maintenance, spam filtering, storage, and availability to the provider in exchange for a recurring fee and less direct control. On-premises email gives full control but requires hardware, patching, security expertise, and careful management of sending reputation.

Cloud email services vs. on-premises email
FactorCloud email servicesOn-premises email
MaintenanceProvider patches and upgradesYour team patches servers, OS, and mail software
AvailabilityProvider's redundancy and published SLADepends on your hardware, power, and internet links
Spam and malware filteringIncluded, trained on large volumes of mailSeparate products to buy and tune
Cost modelPer user per month, or per message for sendingHardware, licenses, and staff time
ControlLimited to the provider's admin settingsFull control of configuration and data location
Remote accessBuilt inRequires publishing services securely to the internet

Scroll the table sideways to see all columns.

For organizations still running Microsoft Exchange Server, the timeline matters. Microsoft ended support for Exchange Server 2016 and Exchange Server 2019 on October 14, 2025, which means no further security updates under standard support. Microsoft's on-premises successor is Exchange Server Subscription Edition (SE), released in July 2025. The alternative is moving mailboxes to a cloud email service such as Exchange Online, or a hybrid setup during the transition.

Common cloud email service providers

For business mailboxes, Microsoft 365 and Google Workspace are the most widely used cloud email services, with Zoho and privacy-focused providers such as Proton as common alternatives. For application sending, Amazon SES and specialist platforms such as SendGrid, Mailgun, and Postmark are widely used.

Microsoft 365 (Exchange Online)

Built on Exchange, with Outlook as the main client. Strong fit for organizations using Windows, Office apps, Teams, and Microsoft Entra ID for identity. Advanced security, compliance, and archiving features depend on the plan.

Google Workspace (Gmail)

Browser-first email with Google Docs, Drive, Meet, and Chat. Popular with startups, schools, and organizations that work mainly in the browser. Security and data governance features also vary by edition.

Zoho Mail and Zoho Workplace

A lower-cost suite often chosen by small businesses, with close ties to Zoho's CRM and business apps.

Privacy-focused providers

Providers such as Proton Mail and Tuta emphasize end-to-end encryption and minimal data collection. Encryption between users of the same service is simple; encrypted mail to outside recipients usually requires a password-protected message or a standard such as PGP.

Sending platforms

Amazon SES suits teams already on AWS that want low-level control. Specialist platforms add richer dashboards, templates, and deliverability support. Compare them on API quality, deliverability tools, dedicated IP options, data retention, and support.

Plans, prices, and feature sets change frequently. Check each provider's current plan comparison for the specific features you need, such as archiving, data loss prevention, or advanced threat protection, since these are often limited to higher tiers.

Running it well

Email authentication and deliverability

Email authentication proves that mail using your domain really comes from you. SPF, DKIM, and DMARC are the three core standards, and major mailbox providers now require them for bulk senders. Setting them up correctly is part of every cloud email service deployment, not an optional extra.

SPF, DKIM, and DMARC

  • SPF (Sender Policy Framework) is a DNS record listing the servers allowed to send mail for your domain. It has a limit of 10 DNS lookups, which organizations using several cloud email services can hit quickly.
  • DKIM (DomainKeys Identified Mail) adds a cryptographic signature to each message. Every service that sends as your domain, including your mailbox provider and any sending platforms, should sign with DKIM for your domain.
  • DMARC ties SPF and DKIM to the visible From address, tells receivers what to do when checks fail (none, quarantine, or reject), and sends you reports. Start with p=none to collect reports, fix every legitimate sender, then move to quarantine and reject.

Bulk sender requirements

Mailbox provider requirements for high-volume senders
ProviderApplies toKey requirementsSince
Google (Gmail)Senders of about 5,000 or more messages a day to Gmail accountsSPF and DKIM, DMARC, alignment, one-click unsubscribe for marketing mail, low spam complaint ratesFebruary 2024
YahooBulk sendersSPF, DKIM, DMARC, one-click unsubscribe, low complaint ratesFebruary 2024
Microsoft (Outlook.com, Hotmail, Live)Senders of more than 5,000 messages a day to consumer Outlook addressesSPF and DKIM must pass, DMARC of at least p=none aligned with SPF or DKIM; non-compliant mail is rejectedMay 5, 2025

Scroll the table sideways to see all columns.

Even below these thresholds, authenticated mail is more likely to reach the inbox. Federal agencies have been required to use DMARC with a reject policy since CISA's Binding Operational Directive 18-01, which is a useful benchmark for any organization.

Other standards worth knowing

MTA-STS tells sending servers they must use encrypted TLS connections when delivering to your domain, and TLS-RPT sends reports when that fails. BIMI lets participating mailbox providers display your logo next to authenticated messages; it requires DMARC at enforcement and, at some providers, a verified mark certificate.

Deliverability basics

  • Send application and marketing mail from separate subdomains so problems in one do not affect staff email.
  • Remove bounced addresses and honor unsubscribes promptly.
  • Warm up new sending IPs or domains gradually rather than sending large volumes on day one.
  • Monitor provider tools such as Google Postmaster Tools and review DMARC reports regularly.

Cloud email security

Securing cloud email means protecting accounts, filtering malicious messages, and preventing impersonation. The provider secures its infrastructure, but account security, configuration, and user behavior remain your responsibility under the cloud shared responsibility model.

The main threats

  • Phishing tricks users into revealing credentials or opening malware.
  • Business email compromise (BEC) uses a compromised or look-alike account to request payments or sensitive data. The FBI's Internet Crime Complaint Center (IC3) consistently ranks BEC among the most financially damaging forms of cybercrime reported to it.
  • Account takeover happens when stolen passwords are used against webmail or legacy protocols.
  • Domain spoofing sends mail that appears to come from your domain, which DMARC at enforcement blocks.

Essential controls

  • Multi-factor authentication on every mailbox, with phishing-resistant methods such as passkeys or security keys for administrators and finance staff.
  • Disable legacy authentication. Protocols that send passwords directly (basic authentication) bypass MFA. Microsoft has disabled basic authentication for most Exchange Online protocols and has announced the retirement of basic authentication for SMTP AUTH client submission; check its current timeline if you have printers, scanners, or applications that send mail this way.
  • Filtering for spam, malware, and impersonation, including warnings for external senders and look-alike domains.
  • Mail forwarding rules monitored or restricted, since attackers often create hidden rules after taking over an account.
  • Data loss prevention policies to catch sensitive data being emailed outside the organization.
  • Encryption in transit (TLS, reinforced by MTA-STS) and message encryption for sensitive content.
  • User training on recognizing phishing and verifying payment requests by phone.

Built-in filtering vs. added email security

Microsoft 365 and Google Workspace include substantial filtering, and many organizations rely on it alone. Others add a third-party service, either a secure email gateway that sits in front of the mailbox by changing MX records, or an API-based tool that connects directly to the mailbox and can remove messages after delivery. The cloud security section of our main guide explains the broader shared responsibility model.

Compliance, retention, and backup

Cloud email services offer retention policies, legal holds, and eDiscovery search, but these are compliance tools, not independent backups. Organizations in regulated industries also need the right contracts, such as a HIPAA business associate agreement, and plan-level features that meet their record-keeping rules.

Regulations and contracts

Healthcare organizations that email protected health information need a business associate agreement (BAA) with their cloud email provider; Microsoft and Google offer BAAs for eligible plans, and HHS has published guidance on HIPAA and cloud computing. Financial firms may face record-retention rules from the SEC or FINRA. Government contractors may need services that meet specific federal requirements. Confirm the exact plan and configuration required, not just that the provider "supports" a regulation.

Retention and eDiscovery

Retention policies keep messages for a set period even if users delete them, and legal holds preserve mailboxes during litigation. eDiscovery tools search across mailboxes and export results. These capabilities often depend on the subscription tier.

Backup

Cloud email providers protect against their own hardware failures, but a deleted mailbox, a malicious insider, a ransomware-encrypted sync, or a misconfigured retention policy can still cause data loss. Providers generally expect customers to manage their own recovery needs. Options include third-party backup services and Microsoft 365 Backup, Microsoft's own backup offering. Test restores the same way you would for servers.

Decisions

How to choose a cloud email service

Choose a cloud email service by starting with how your team works: the office apps and identity system you already use, your security and compliance requirements, the features you need at each plan level, and whether you also need a separate service for application or marketing email.

Matching needs to cloud email options
If you...Consider
Use Windows, Office desktop apps, and TeamsMicrosoft 365
Work mainly in the browser with shared documentsGoogle Workspace
Are a small business watching costsEntry plans from the major suites, or Zoho
Handle especially sensitive communicationsA privacy-focused provider, or advanced encryption features in a major suite
Send receipts, alerts, or password resets from an appA transactional email platform such as Amazon SES
Run newsletters and campaignsA marketing email platform
Need specific integration or data location controlA hosted or self-managed mail server, with the extra operational work that implies

Scroll the table sideways to see all columns.

Evaluation checklist

  • Mailbox size and archive limits per plan, and what happens when users exceed them.
  • Identity integration: single sign-on, MFA options, and conditional access.
  • Security features included at your plan level: phishing protection, DLP, encryption, audit logs.
  • Compliance: retention, eDiscovery, legal hold, BAA availability, and data residency options.
  • Client support: desktop, mobile, and web apps your users prefer, plus IMAP or API access for integrations.
  • Availability: the published SLA and the provider's status history.
  • Migration tools for your current system.
  • Admin experience: user management, shared mailboxes, groups, and reporting.
  • Total cost including add-ons for security, archiving, and backup.

Migrating to cloud email services

Moving to a cloud email service involves preparing DNS and accounts, copying existing mail, switching your MX records, and then fixing authentication and client settings. Most of the risk is in planning: missed senders, forgotten shared mailboxes, and devices that still use old settings.

  1. InventoryList mailboxes, shared mailboxes, aliases, distribution lists, forwarding rules, and every system that sends mail as your domain (websites, CRM, printers, applications).
  2. Lower DNS TTLsA day or more before cutover, reduce the time-to-live on MX and related records so the change takes effect quickly.
  3. Set up the new serviceVerify your domain, create users and groups, and configure security settings and MFA.
  4. Copy existing mailUse the provider's migration tools (for example, IMAP, cutover, staged, or hybrid migration for Exchange, or Google's migration tools) to copy mail, calendars, and contacts. Large mailboxes can take days, so start early.
  5. Switch MX recordsPoint MX to the new provider and run a final synchronization of any mail that arrived during the switch.
  6. Update authenticationUpdate SPF, enable DKIM signing on the new provider, and review DMARC reports for senders you missed.
  7. Reconfigure clients and devicesHelp users set up apps and phones, and move scanners and applications to supported sending methods.
  8. Decommission carefullyKeep the old system available read-only for a period, confirm archives and backups, then shut it down.

For the general cloud migration process, see the cloud migration section of our main guide.

Cost considerations for cloud email services

Business cloud email services are usually priced per user per month, with higher tiers adding security, compliance, and storage. Sending platforms usually charge by message volume. The total cost often depends more on add-ons and plan choices than on the base mailbox price.

Prices change often, so this guide does not quote them. Factors to compare include:

  • The plan tier each user needs, since not every user needs the most expensive license
  • Shared mailboxes and resource accounts, which are often free or cheaper than user licenses
  • Security add-ons such as advanced threat protection or a third-party email security service
  • Archiving, eDiscovery, and backup services
  • Sending volume, dedicated IP addresses, and data retention on transactional platforms
  • Annual vs. monthly commitments, and nonprofit or education pricing where eligible
  • One-time migration effort, whether internal or outsourced

Getting outside help with cloud email

Many small and mid-size organizations use an IT provider or cloud specialist for email migrations, DNS and authentication setup, security hardening, and ongoing administration. It is one of the most common starting points for outside cloud help.

Typical engagements include migrating from an older server or another provider, setting up SPF, DKIM, and DMARC to enforcement, configuring security policies, and ongoing user management through a managed service. Some providers also bundle managed cloud security services for email monitoring and response. Our guide to cloud tech services explains provider types, pricing models, contracts, and how to evaluate a provider.

Reference

Cloud email services FAQs

What are cloud email services?

Cloud email services are email systems hosted by a provider on its own infrastructure and delivered over the internet. They include business mailbox hosting such as Microsoft 365 and Google Workspace, sending platforms for application and marketing email such as Amazon SES, and related security, archiving, and backup services.

What is the best cloud email service for business?

For most businesses, the choice is between Microsoft 365 and Google Workspace, and the better fit usually depends on the office apps and identity system you already use. Smaller businesses sometimes choose Zoho for cost, and privacy-sensitive teams consider providers such as Proton. Compare features at the specific plan level you will buy.

Is cloud email more secure than an on-premises email server?

For most organizations, yes, because major providers patch continuously and run large-scale filtering and monitoring. Security still depends on your configuration: MFA, disabling legacy authentication, DMARC, and user training remain your responsibility.

Do I need SPF, DKIM, and DMARC?

Yes. Google, Yahoo, and Microsoft require them for bulk senders, and they improve deliverability and protect your domain from spoofing for everyone else. Configure SPF and DKIM for every service that sends mail as your domain, then move DMARC from monitoring to enforcement.

What is the difference between email hosting and an email sending service?

Email hosting provides mailboxes that people use to send, receive, and store mail. An email sending service delivers automated or bulk messages from applications and marketing tools through an API or SMTP, with tools for bounces, complaints, and deliverability. Most organizations use both.

Can I keep my domain name when I move to cloud email?

Yes. You verify your domain with the provider and update your DNS records, including MX, SPF, DKIM, and DMARC. Your email addresses stay the same.

Does Microsoft 365 or Google Workspace back up my email?

They protect against their own infrastructure failures and offer retention features, but these are not the same as an independent backup you control. For protection against deletion, ransomware, or configuration mistakes, consider a backup service and test restores.

What happens to Exchange Server 2016 and 2019?

Microsoft ended support for both on October 14, 2025. Organizations running them should upgrade to Exchange Server Subscription Edition or move mailboxes to a cloud email service such as Exchange Online.

How long does an email migration take?

A small business can often switch in a few days to a couple of weeks. Larger organizations take longer, mainly because of mailbox sizes, the number of sending systems to update, and user support. Copying mail usually starts before the MX switch so the cutover itself is short.

Sources and further reading

Requirements and dates in this guide come from the following primary sources. Provider requirements change, so check the current pages before making decisions.

  1. Google Workspace Admin Help, Email sender guidelines
  2. Yahoo, Sender best practices
  3. Microsoft, Outlook's new requirements for high-volume senders
  4. Microsoft, Exchange Server 2019 and 2016 end of support
  5. Microsoft, Exchange Server Subscription Edition is now available
  6. Microsoft, Updated SMTP AUTH basic authentication deprecation timeline
  7. Microsoft, Microsoft 365 Backup overview
  8. IETF, RFC 7208: Sender Policy Framework (SPF)
  9. IETF, RFC 6376: DomainKeys Identified Mail (DKIM)
  10. IETF, RFC 7489: DMARC
  11. IETF, RFC 8461: SMTP MTA Strict Transport Security (MTA-STS)
  12. IETF, RFC 8058: One-click unsubscribe
  13. CISA, BOD 18-01: Enhance Email and Web Security
  14. HHS, Guidance on HIPAA and cloud computing
  15. FBI, Internet Crime Complaint Center (IC3)
  16. AWS, Amazon Simple Email Service

About this guide

This guide is published by Crecso as an independent educational resource and is part of our cloud technology guide. It names products and providers as examples only, is not affiliated with any email provider, and does not describe services offered by Crecso.

Last reviewed on . If you spot something that has changed, please let us know through our contact page.