Dept. of migrations · AWS WorkMail alternatives
WorkMail closes in 2027.
Here's where to go.
AWS ends support for Amazon WorkMail on 31 March 2027; it has been closed to new customers since 30 April 2026. Every remaining customer has to move. AWS itself points to Kopano Cloud, Zoho Mail and Zoom Mail, and Google Workspace and Microsoft 365 are the usual destinations for teams. Folio is the right answer for one specific case — a single operator running several domains from one inbox — and the wrong one if you need mailboxes for staff. Whichever you pick, the mail itself moves over IMAP: Folio reads your WorkMail mailbox and imports it automatically, and a separate DNS cutover routes new mail once cached records refresh.
AWS WorkMail support ends 31 March 2027AWS notice →
This isn't an export-then-upload workflow. Connect your WorkMail mailbox over IMAP after signup and Folio reads it in full — every message and its attachments — while you handle the DNS side below at your own pace.
Type your domain to personalize the records. The DNS steps run independently of the import — do them in either order, or the same afternoon.
Not sure Folio is the right destination? Start with the alternatives below — including the three AWS itself recommends, and the cases where one of them beats us outright.
Updated 4 September 2026 (2026-09-04)
The WorkMail switch kit · no signup needed
A checklist you can take with you.
Use this with any destination. AWS ends WorkMail support on 31 March 2027; finish and verify your move while the original mailbox is still accessible.
- Inventory every address, alias, folder, calendar and contact list. Count people who need separate access, not just addresses.
- Choose a destination that covers those needs. Save a separate backup and verify that you can open it.
- Test one mailbox import before changing MX. Check old and recent messages, attachments and folders; handle calendar and contact data separately.
- Prepare the new provider’s domain records. Keep one SPF policy and one DMARC policy per name; preserve other legitimate senders.
- Lower MX TTL and wait out the previous TTL before cutover. Save the original records so you can roll back.
- Switch MX only after testing. Keep WorkMail active during DNS propagation, check both inboxes and reconcile mail that arrived during the overlap.
- Test incoming mail and replies from each address. Retire WorkMail only after checking the final copy and your separate backup.
Plain-text Markdown: save it, edit it or share it with whoever manages your DNS. No email address or mailbox credentials required.
Would Folio fit your move?
Folio is for one person handling several business identities. It is not a shared team inbox or an Exchange replacement.
Choose who needs access to see whether Folio is worth evaluating. Your answers stay on this page.
The options, including the ones that aren't us
AWS names three.
The end-of-support notice points customers at Kopano Cloud, Zoho Mail and Zoom Mail. All three are per-user products, because WorkMail was a per-user product. If you have staff, one of these is probably your answer and you can stop reading here.
Zoho Mail →
Per user, per month, from about $1/user on Mail Lite
Teams that want the closest like-for-like: mailboxes per person, shared mailboxes, an admin console, calendar and contacts included.
Kopano Cloud →
Per user, per month
Organisations that were using WorkMail as Exchange-style groupware — shared calendars, ActiveSync devices, on-prem-adjacent control.
Zoom Mail →
Bundled with Zoom Workplace plans
Teams already paying for Zoom that would rather consolidate a bill than run a separate mail vendor.
The wider field, by how it bills you.
Feature lists all look the same at this price point. Billing shape is what actually decides the invoice for someone running more than one business, so that is the axis below.
| Destination | Billing | What it's good at | Pick it if |
|---|---|---|---|
| Google Workspace | ~$7 / user / month | Docs, Drive, Meet and the calendar everyone already knows how to use. | You have staff, or you want the office suite as well as the mail. |
| Microsoft 365 Business Basic | ~$7 / user / month | Outlook, Teams and the Office apps; the closest thing to WorkMail's Exchange behaviour. | You came to WorkMail from Exchange and want to go back to it. |
| Zoho Mail | from ~$1 / user / month | AWS's own first-named alternative; per-user mailboxes at the lowest credible price. | You need several people's mailboxes and the budget is the binding constraint. |
| Migadu · Purelymail | $19 / yr · $10 / yr, flat | Unlimited domains for the price of a sandwich, if you bring your own IMAP client. | You are comfortable in Thunderbird or mutt and want the cheapest possible bill. |
| Folio | per operator, never per seat | Every domain in one inbox, replies auto-sent from the domain the message arrived on, per-domain DKIM generated at bind time, and an IMAP import that reads your WorkMail mailbox for you. | You are one person running several businesses, and WorkMail's per-user bill never matched how you actually work. |
Competitor prices were last checked 15 August 2026; confirm current terms with each vendor. We publish this table and we are not the cheapest row on it — Migadu and Purelymail are, by a wide margin, and if you are happy in a desktop IMAP client they are the better buy. What the gap pays for is one inbox across every domain instead of one account per domain, a reply-From chosen automatically by the domain the message arrived on, and per-domain DKIM generated when the domain is bound. Folio's own pricing is on the pricing page, from $3.50 a month.
Working backwards from the AWS date
The real deadline is earlier.
You want the move finished while the old mailbox still opens. Anything you discover missing after 31 March 2027 is not recoverable from anywhere, because the source is gone.
30 April 2026
Closed to new customers
Already passed. If you are on WorkMail today you are in the group that has to move.
By 31 December 2026
Import and cut over
Leaves a full quarter of overlap while WorkMail still works, so anything you find missing is recoverable from the source rather than from a backup.
By 28 February 2027
Export what IMAP can't carry
Calendars, contacts and any compliance archive, via AWS's mailbox export guide. These do not travel over IMAP and there is no second chance after the shutdown.
31 March 2027
WorkMail ends
AWS states you will no longer be able to use Amazon WorkMail or reach its console. Nothing left behind is retrievable after this date.
Where your mail is at each step
The stages below are the ones spelled out further down this page. Every one of them can be undone — except the last, and that one is AWS's to make, not yours. It is the whole reason to start early rather than carefully.
Stage 0 — lower the TTL
Nothing has moved. All of it — history and new mail — is still in WorkMail. You have only shortened how long resolvers cache your MX.
ReversibleNothing to undo. This step is what makes every later step quick to reverse.
Stage I — import, and test
Folio holds a copy of your history and you send a test message. Your WorkMail MX is still in place, so real mail keeps arriving where it always did.
ReversibleWalk away and change nothing. Your live mail never moved.
Stage II — replace the MX
You delete the WorkMail MX row, leaving Folio's as the only one. New mail begins arriving in Folio as resolvers refresh. WorkMail still holds everything it already had.
ReversiblePut the WorkMail MX row back. Because you lowered the TTL in Stage 0, resolvers pick that up in minutes rather than a day.
WorkMail ends
31 March 2027
AWS states you can no longer use Amazon WorkMail or reach its console. Anything left behind goes with it — including calendars, contacts and archives, which IMAP import does not carry.
Cannot be undoneThere is no source left to go back to.
Two MX records do not give you a duplicate copy of every message. Folio does not guarantee an uninterrupted cutover — you test in Stage I and verify in Stage II, while WorkMail is still readable.
Before you commit to this path
What doesn't come with you.
WorkMail is Exchange-style groupware for organisations. Folio is one inbox for one operator. Some of what WorkMail did for you has no equivalent here, and it is cheaper for both of us if you find that out now.
- Calendars and contacts
- IMAP carries mail and attachments, not calendar or address-book data. Export them from the WorkMail console before the shutdown. Folio has its own calendar, but it does not import WorkMail's.
- Staff mailboxes
- Folio is single-operator: one account, one person, many domains. If other people need their own mailbox on your domain, Folio is the wrong destination today — Zoho Mail, Google Workspace or Microsoft 365 are the honest answers.
- Shared mailboxes and distribution groups
- WorkMail's group and resource mailboxes have no equivalent. A catch-all alias covers some of what a distribution list was doing; it does not cover several people reading one queue.
- Exchange ActiveSync and MAPI clients
- Folio is a web app with IMAP-style semantics, not an Exchange server. Outlook profiles bound to WorkMail over ActiveSync will not transfer.
- Journaling, retention and legal hold
- If you are under a retention obligation, export from WorkMail while it still exists and keep that archive somewhere that meets the obligation. Do not treat any migration as your compliance copy.
Export anything in that list from WorkMail while it still exists — AWS documents the procedure in its mailbox export guide.
The part that isn't manual
Connect once. Folio reads the mailbox.
After signup, open Migrate from AWS WorkMail from your dashboard, enter your WorkMail address and an IMAP password, and Folio imports your historical mail as a background job — dedupe means a re-run never creates copies, and you can check progress or walk away and come back. Nothing is ever exported by hand.
The credential is used once, over an IMAPS (TLS) connection on port 993, then discarded — never written to a database or a log, and never held past the import job. Details on Folio's trust center →
Is this migration right for you?
- You need your mail moved. The import brings over your messages and their attachments. Calendars and contacts aren't carried over IMAP — export those from the WorkMail console separately.
- One mailbox at a time. Run it once per mailbox, each with its own WorkMail address and password. Ideal for a solo operator or a few inboxes, not a bulk org-wide migration in a single pass.
- Your WorkMail region is supported. Pick it below — the eight common regions are covered.
- You can get an IMAP password. If your organization uses SSO, generate an app-specific password in the WorkMail management console.
- You'd rather not wait until 2027. Support ends 31 March 2027; moving now leaves plenty of room to check everything landed.
- You want a permanent inbox, not a temporary one. This is a full mailbox migration. If you actually just need a disposable address for one signup or a single thread, Emcognito handles that instead, free — no need to move anything.
New to DNS? Start here
DNS is just the internet's phone book — it's how "yourdomain.com" tells the world where to send things. An MX record is the one line in that phone book that says "deliver mail here." A TXT record is a small text stamp that proves you're allowed to send mail as your domain, so spam filters trust it. Below, you're only ever touching those mail-routing lines — not your website, not your files, nothing else on the domain changes.
If any of this still feels unfamiliar once you're in your registrar's dashboard, use the authenticated domain wizard for the exact records for your account. The examples below do not inspect your existing SPF, DMARC or other sending services.
Preflight · before the DNS cutover
Lower the TTL.
The cutover itself takes seconds — remove one MX row, keep the other. The slow part is DNS propagation, capped by however long resolvers cache your current MX. Give yourself rollback insurance before you touch anything else.
- i Open your registrar (Route 53). Find the MX record for
your-domain.com. - iiLower its TTL to
300. Save. - iiiWait at least the previous TTL before cutover — or start the mail import in the meantime.
Stage I · prepare and verify before cutover
Review the record examples.
Leave MX unchanged until the new mailbox is ready. Use the authenticated domain wizard for exact values, including your domain-specific DKIM key. Merge legitimate senders into one SPF policy and keep one DMARC policy per name; do not add duplicate policies or switch to reject before checking alignment. Save the old records for rollback.
№ 01MX - Host
- your-domain.com
- Value
- 10 inbound.wm.emcognito.com
Folio's inbound MTA becomes the domain's mail receiver. Priority 10 — no backup record needed.
№ 02TXT - Host
- your-domain.com
- Value
- v=spf1 include:emcognito.com ~all
SPF authorizes Folio's outbound IPs. DMARC below is what actually enforces alignment.
№ 03TXT - Host
- _dmarc.your-domain.com
- Value
- v=DMARC1; p=reject; sp=reject; adkim=s; aspf=r; rua=mailto:dmarc-rua@your-domain.com
Strict DKIM-aligned DMARC. Reports flow to your own dmarc-rua@ address, a receive-only mailbox Folio manages — don't add another _dmarc record.
Hosted zones → your domain → Create record. Route 53 is also where most WorkMail organizations already keep their MX — look for a record with a WorkMail-managed comment before deleting it.
Two more records — per-domain DKIM and SES verification — are account-specific and get generated when you sign up. The in-app domain wizard hands you those values alongside its other domain records. Verify them before changing MX.
Stage II · the cutover · after testing
Replace WorkMail's MX.
Once the Folio mailbox and sender authentication are ready, replace the WorkMail MX with the Folio MX shown in your domain wizard. Two MX records do not provide a duplicate copy of every message. AWS WorkMail's documented inbound format is 10 inbound-smtp.<region>.amazonaws.com — confirm the exact row in your own DNS panel before deleting; the region picker above fills in the expected value for reference.
your-domain.com- 10 inbound-smtp.us-east-1.amazonaws.com
The MX added in Stage I is now the only one on your-domain.com. New mail begins arriving in Folio as resolvers refresh within the TTL window from Stage 0.
Open the first letter
Bring your-domain.com
home.
Sign up, connect WorkMail for the automatic import, and publish the DNS records above in whichever order suits you — both finish on their own timeline, and neither blocks the other.
WorkMail billed per mailbox. Folio is flat — every domain you own, one price, from $3.50/mo · full pricing →
No card needed. The first domain you bind and the first 100 sends are free.
Common questions
Questions WorkMail switchers ask.
What are the alternatives to AWS WorkMail?
- AWS's own end-of-support notice names three: Zoho Mail, Kopano Cloud and Zoom Mail. In practice most teams leaving WorkMail land on Google Workspace or Microsoft 365, both about $7 per user per month, because they need mailboxes for staff and an office suite alongside. Folio is a narrower answer: single-operator, priced per operator rather than per seat, and built for one person running several domains from one inbox. If you need mailboxes for other people, pick one of the others — that is not what Folio does.
What happens on 31 March 2027 if I do nothing?
- AWS states that after 31 March 2027 you will no longer be able to use Amazon WorkMail or access its console. Mail stops being delivered and stored mail stops being reachable. There is no stated grace period, so anything you have not exported or migrated by then is gone. WorkMail has been closed to new customers since 30 April 2026, so every remaining account is in the group that has to move.
Is AWS WorkMail being discontinued, or just deprecated?
- Discontinued. AWS is ending support entirely on 31 March 2027 rather than freezing the feature set — the service itself stops. This is not a version deprecation you can sit out.
Does Folio really import my mail automatically, or do I still have to export it myself?
- Folio connects directly to your WorkMail mailbox over IMAP and pulls every message itself — you don't export a file or upload anything. You enter your WorkMail address and an IMAP-capable password once, Folio reads your folders, and the import runs as a background job you can check on.
Is my WorkMail password stored anywhere?
- No. It's used once, to open the IMAP connection for the import, and is never written to a database, a log, or anywhere else. If the import needs to be re-run later, you re-enter it — nothing persists between sessions.
Will mail bounce during the DNS cutover?
- A migration cannot guarantee zero downtime. Prepare and test the destination first, lower MX TTL and wait out the previous TTL, then switch MX. Keep WorkMail active during propagation, check both inboxes, and reconcile messages received during the overlap. Publishing two MX records does not copy each message to both providers.
What if my organization requires an app-specific password for IMAP?
- Use it — that's the recommended credential for this import, not your primary WorkMail/SSO password. AWS WorkMail administrators can generate app passwords from the WorkMail management console if IMAP access needs one.
Can I import more than one WorkMail mailbox?
- Yes — run the import once per mailbox. Each mailbox is its own IMAP connection, with its own WorkMail address and password, and each domain still gets its own DNS cutover. It's built for a solo operator or a handful of inboxes, not a bulk admin migration across an entire organization in one pass.
Does Folio move my WorkMail calendar and contacts too?
- Not currently. The import runs over IMAP, which carries mail and its attachments but not calendars or contacts. Export those from the WorkMail console separately before support ends on 31 March 2027 if you need to keep them.
Do I have to commit to the full move before I know it worked?
- No. The import only reads from WorkMail over IMAP — it never deletes or modifies anything there, so your existing mailbox stays exactly as it was. Run the import, check that everything landed correctly in Folio, and only start the DNS cutover once you're satisfied. The two steps are independent; nothing about connecting WorkMail commits you to flipping DNS.
Sources & further reading
- Amazon WorkMail — End of support (retirement timeline)
- Amazon WorkMail — Exporting mailbox content
- Zoho Mail — AWS WorkMail alternative (named by AWS)
- Kopano Cloud — WorkMail migration (named by AWS)
- Zoom Mail — Amazon WorkMail (named by AWS)
- Amazon WorkMail — Verifying domains
- Amazon WorkMail — Inbound email
- Amazon Route 53 — Routing traffic to Amazon WorkMail
- RFC 7208 — Sender Policy Framework (SPF)
- RFC 7489 — DMARC