Dept. of migrations · AWS WorkMail alternatives

WorkMail closes in 2027.
Here's where to go.

AWS ends support for Amazon WorkMail on 31 March 2027; it has been closed to new customers since 30 April 2026. Every remaining customer has to move. AWS itself points to Kopano Cloud, Zoho Mail and Zoom Mail, and Google Workspace and Microsoft 365 are the usual destinations for teams. Folio is the right answer for one specific case — a single operator running several domains from one inbox — and the wrong one if you need mailboxes for staff. Whichever you pick, the mail itself moves over IMAP: Folio reads your WorkMail mailbox and imports it automatically, and a separate ten-minute DNS cutover moves new mail across.

AWS WorkMail support ends 31 March 2027AWS notice →

Import my WorkMail →Free to start · the import only reads your mailbox — nothing in WorkMail is deleted or changed

This isn't an export-then-upload workflow. Connect your WorkMail mailbox over IMAP after signup and Folio reads it in full — every message and its attachments — while you handle the DNS side below at your own pace.

Type your domain to personalize the records. The DNS steps run independently of the import — do them in either order, or the same afternoon.

Not sure Folio is the right destination? Start with the alternatives below — including the three AWS itself recommends, and the cases where one of them beats us outright.

Updated 15 August 2026 (2026-08-15)

The options, including the ones that aren't us

AWS names three.

The end-of-support notice points customers at Kopano Cloud, Zoho Mail and Zoom Mail. All three are per-user products, because WorkMail was a per-user product. If you have staff, one of these is probably your answer and you can stop reading here.

  • Zoho Mail →

    Per user, per month, from about $1/user on Mail Lite

    Teams that want the closest like-for-like: mailboxes per person, shared mailboxes, an admin console, calendar and contacts included.

  • Kopano Cloud →

    Per user, per month

    Organisations that were using WorkMail as Exchange-style groupware — shared calendars, ActiveSync devices, on-prem-adjacent control.

  • Zoom Mail →

    Bundled with Zoom Workplace plans

    Teams already paying for Zoom that would rather consolidate a bill than run a separate mail vendor.

The wider field, by how it bills you.

Feature lists all look the same at this price point. Billing shape is what actually decides the invoice for someone running more than one business, so that is the axis below.

DestinationBillingWhat it's good atPick it if
Google Workspace~$7 / user / monthDocs, Drive, Meet and the calendar everyone already knows how to use.You have staff, or you want the office suite as well as the mail.
Microsoft 365 Business Basic~$7 / user / monthOutlook, Teams and the Office apps; the closest thing to WorkMail's Exchange behaviour.You came to WorkMail from Exchange and want to go back to it.
Zoho Mailfrom ~$1 / user / monthAWS's own first-named alternative; per-user mailboxes at the lowest credible price.You need several people's mailboxes and the budget is the binding constraint.
Migadu · Purelymail$19 / yr · $10 / yr, flatUnlimited domains for the price of a sandwich, if you bring your own IMAP client.You are comfortable in Thunderbird or mutt and want the cheapest possible bill.
Folioper operator, never per seatEvery domain in one inbox, replies auto-sent from the domain the message arrived on, per-domain DKIM generated at bind time, and an IMAP import that reads your WorkMail mailbox for you.You are one person running several businesses, and WorkMail's per-user bill never matched how you actually work.

Prices are each vendor's own list price, checked 15 August 2026. We publish this table and we are not the cheapest row on it — Migadu and Purelymail are, by a wide margin, and if you are happy in a desktop IMAP client they are the better buy. What the gap pays for is one inbox across every domain instead of one account per domain, a reply-From chosen automatically by the domain the message arrived on, and per-domain DKIM generated when the domain is bound. Folio's own pricing is on the pricing page, from $3.50 a month.

Working backwards from the AWS date

The real deadline is earlier.

You want the move finished while the old mailbox still opens. Anything you discover missing after 31 March 2027 is not recoverable from anywhere, because the source is gone.

  1. 30 April 2026

    Closed to new customers

    Already passed. If you are on WorkMail today you are in the group that has to move.

  2. By 31 December 2026

    Import and cut over

    Leaves a full quarter of overlap while WorkMail still works, so anything you find missing is recoverable from the source rather than from a backup.

  3. By 28 February 2027

    Export what IMAP can't carry

    Calendars, contacts and any compliance archive, via AWS's mailbox export guide. These do not travel over IMAP and there is no second chance after the shutdown.

  4. 31 March 2027

    WorkMail ends

    AWS states you will no longer be able to use Amazon WorkMail or reach its console. Nothing left behind is retrievable after this date.

Before you commit to this path

What doesn't come with you.

WorkMail is Exchange-style groupware for organisations. Folio is one inbox for one operator. Some of what WorkMail did for you has no equivalent here, and it is cheaper for both of us if you find that out now.

Calendars and contacts
IMAP carries mail and attachments, not calendar or address-book data. Export them from the WorkMail console before the shutdown. Folio has its own calendar, but it does not import WorkMail's.
Staff mailboxes
Folio is single-operator: one account, one person, many domains. If other people need their own mailbox on your domain, Folio is the wrong destination today — Zoho Mail, Google Workspace or Microsoft 365 are the honest answers.
Shared mailboxes and distribution groups
WorkMail's group and resource mailboxes have no equivalent. A catch-all alias covers some of what a distribution list was doing; it does not cover several people reading one queue.
Exchange ActiveSync and MAPI clients
Folio is a web app with IMAP-style semantics, not an Exchange server. Outlook profiles bound to WorkMail over ActiveSync will not transfer.
Journaling, retention and legal hold
If you are under a retention obligation, export from WorkMail while it still exists and keep that archive somewhere that meets the obligation. Do not treat any migration as your compliance copy.

Export anything in that list from WorkMail while it still exists — AWS documents the procedure in its mailbox export guide.

The part that isn't manual

Connect once. Folio reads the mailbox.

After signup, open Migrate from AWS WorkMail from your dashboard, enter your WorkMail address and an IMAP password, and Folio imports your historical mail as a background job — dedupe means a re-run never creates copies, and you can check progress or walk away and come back. Nothing is ever exported by hand.

The credential is used once, over an IMAPS (TLS) connection on port 993, then discarded — never written to a database or a log, and never held past the import job. Details on Folio's trust center →

Is this migration right for you?

  • You need your mail moved. The import brings over your messages and their attachments. Calendars and contacts aren't carried over IMAP — export those from the WorkMail console separately.
  • One mailbox at a time. Run it once per mailbox, each with its own WorkMail address and password. Ideal for a solo operator or a few inboxes, not a bulk org-wide migration in a single pass.
  • Your WorkMail region is supported. Pick it below — the eight common regions are covered.
  • You can get an IMAP password. If your organization uses SSO, generate an app-specific password in the WorkMail management console.
  • You'd rather not wait until 2027. Support ends 31 March 2027; moving now leaves plenty of room to check everything landed.
  • You want a permanent inbox, not a temporary one. This is a full mailbox migration. If you actually just need a disposable address for one signup or a single thread, Emcognito handles that instead, free — no need to move anything.
Proof of move · enter once, used throughout
Registrar

New to DNS? Start here

DNS is just the internet's phone book — it's how "yourdomain.com" tells the world where to send things. An MX record is the one line in that phone book that says "deliver mail here." A TXT record is a small text stamp that proves you're allowed to send mail as your domain, so spam filters trust it. Below, you're only ever touching those mail-routing lines — not your website, not your files, nothing else on the domain changes.

If any of this still feels unfamiliar once you're in your registrar's dashboard, the record cards below are built to be copy-pasted exactly as shown — you don't need to understand DNS to get it right, just to paste carefully.

Preflight · before the DNS cutover

Lower the TTL.

The cutover itself takes seconds — remove one MX row, keep the other. The slow part is DNS propagation, capped by however long resolvers cache your current MX. Give yourself rollback insurance before you touch anything else.

  1. i Open your registrar (Route 53). Find the MX record for your-domain.com.
  2. iiLower its TTL to 300. Save.
  3. iiiWait an hour, then continue to Stage I — or start the mail import in the meantime.

Stage I · no downtime · safe at any time

Add Folio's three records.

Publish these alongside your existing WorkMail records. Mail keeps flowing through WorkMail; nothing changes yet.

  1. № 01MX
    Host
    your-domain.com
    Value
    10 inbound.wm.emcognito.com

    Folio's inbound MTA becomes the domain's mail receiver. Priority 10 — no backup record needed.

  2. № 02TXT
    Host
    your-domain.com
    Value
    v=spf1 include:emcognito.com ~all

    SPF authorizes Folio's outbound IPs. DMARC below is what actually enforces alignment.

  3. № 03TXT
    Host
    _dmarc.your-domain.com
    Value
    v=DMARC1; p=reject; sp=reject; adkim=s; aspf=r; rua=mailto:dmarc-rua@your-domain.com

    Strict DKIM-aligned DMARC. Reports flow to your own dmarc-rua@ address, a receive-only mailbox Folio manages — don't add another _dmarc record.

On Route 53

Hosted zones → your domain → Create record. Route 53 is also where most WorkMail organizations already keep their MX — look for a record with a WorkMail-managed comment before deleting it.

Two more records — per-domain DKIM and SES verification — are account-specific and get generated when you sign up. The in-app domain wizard hands you those values in the same place you pasted these.

Stage II · the cutover · about five minutes

Remove WorkMail's MX.

Folio's MX sits inert until WorkMail's row is gone. AWS WorkMail's documented inbound format is 10 inbound-smtp.<region>.amazonaws.com — confirm the exact row in your own DNS panel before deleting; the region picker above fills in the expected value for reference.

Delete thisfrom the MX records on your-domain.com
  1. 10 inbound-smtp.us-east-1.amazonaws.com

Match what's actually published for your domain — the region above is a starting point, not a substitute for checking your WorkMail admin console or DNS panel directly.

The MX added in Stage I is now the only one on your-domain.com. New mail begins arriving in Folio as resolvers refresh within the TTL window from Stage 0.


Open the first letter

Bring your-domain.com
home.

Sign up, connect WorkMail for the automatic import, and publish the DNS records above in whichever order suits you — both finish on their own timeline, and neither blocks the other.

WorkMail billed per mailbox. Folio is flat — every domain you own, one price, from $3.50/mo · full pricing →

No card needed. The first domain you bind and the first 100 sends are free.

Common questions

Questions WorkMail switchers ask.

What are the alternatives to AWS WorkMail?

AWS's own end-of-support notice names three: Zoho Mail, Kopano Cloud and Zoom Mail. In practice most teams leaving WorkMail land on Google Workspace or Microsoft 365, both about $7 per user per month, because they need mailboxes for staff and an office suite alongside. Folio is a narrower answer: single-operator, priced per operator rather than per seat, and built for one person running several domains from one inbox. If you need mailboxes for other people, pick one of the others — that is not what Folio does.

What happens on 31 March 2027 if I do nothing?

AWS states that after 31 March 2027 you will no longer be able to use Amazon WorkMail or access its console. Mail stops being delivered and stored mail stops being reachable. There is no stated grace period, so anything you have not exported or migrated by then is gone. WorkMail has been closed to new customers since 30 April 2026, so every remaining account is in the group that has to move.

Is AWS WorkMail being discontinued, or just deprecated?

Discontinued. AWS is ending support entirely on 31 March 2027 rather than freezing the feature set — the service itself stops. This is not a version deprecation you can sit out.

Does Folio really import my mail automatically, or do I still have to export it myself?

Folio connects directly to your WorkMail mailbox over IMAP and pulls every message itself — you don't export a file or upload anything. You enter your WorkMail address and an IMAP-capable password once, Folio reads your folders, and the import runs as a background job you can check on.

Is my WorkMail password stored anywhere?

No. It's used once, to open the IMAP connection for the import, and is never written to a database, a log, or anywhere else. If the import needs to be re-run later, you re-enter it — nothing persists between sessions.

Will mail bounce during the DNS cutover?

No, if you follow the overlap plan below: lower your MX TTL first, publish Folio's records alongside WorkMail's, then remove WorkMail's MX. Both mail servers accept inbound mail during the overlap window.

What if my organization requires an app-specific password for IMAP?

Use it — that's the recommended credential for this import, not your primary WorkMail/SSO password. AWS WorkMail administrators can generate app passwords from the WorkMail management console if IMAP access needs one.

Can I import more than one WorkMail mailbox?

Yes — run the import once per mailbox. Each mailbox is its own IMAP connection, with its own WorkMail address and password, and each domain still gets its own DNS cutover. It's built for a solo operator or a handful of inboxes, not a bulk admin migration across an entire organization in one pass.

Does Folio move my WorkMail calendar and contacts too?

Not currently. The import runs over IMAP, which carries mail and its attachments but not calendars or contacts. Export those from the WorkMail console separately before support ends on 31 March 2027 if you need to keep them.

Do I have to commit to the full move before I know it worked?

No. The import only reads from WorkMail over IMAP — it never deletes or modifies anything there, so your existing mailbox stays exactly as it was. Run the import, check that everything landed correctly in Folio, and only start the DNS cutover once you're satisfied. The two steps are independent; nothing about connecting WorkMail commits you to flipping DNS.

Sources & further reading