Dept. of migrations · AWS WorkMail alternatives
WorkMail closes in 2027.
Here's where to go.
AWS ends support for Amazon WorkMail on 31 March 2027; it has been closed to new customers since 30 April 2026. Every remaining customer has to move. AWS itself points to Kopano Cloud, Zoho Mail and Zoom Mail, and Google Workspace and Microsoft 365 are the usual destinations for teams. Folio is the right answer for one specific case — a single operator running several domains from one inbox — and the wrong one if you need mailboxes for staff. Whichever you pick, the mail itself moves over IMAP: Folio reads your WorkMail mailbox and imports it automatically, and a separate ten-minute DNS cutover moves new mail across.
AWS WorkMail support ends 31 March 2027AWS notice →
This isn't an export-then-upload workflow. Connect your WorkMail mailbox over IMAP after signup and Folio reads it in full — every message and its attachments — while you handle the DNS side below at your own pace.
Type your domain to personalize the records. The DNS steps run independently of the import — do them in either order, or the same afternoon.
Not sure Folio is the right destination? Start with the alternatives below — including the three AWS itself recommends, and the cases where one of them beats us outright.
Updated 15 August 2026 (2026-08-15)
The options, including the ones that aren't us
AWS names three.
The end-of-support notice points customers at Kopano Cloud, Zoho Mail and Zoom Mail. All three are per-user products, because WorkMail was a per-user product. If you have staff, one of these is probably your answer and you can stop reading here.
Zoho Mail →
Per user, per month, from about $1/user on Mail Lite
Teams that want the closest like-for-like: mailboxes per person, shared mailboxes, an admin console, calendar and contacts included.
Kopano Cloud →
Per user, per month
Organisations that were using WorkMail as Exchange-style groupware — shared calendars, ActiveSync devices, on-prem-adjacent control.
Zoom Mail →
Bundled with Zoom Workplace plans
Teams already paying for Zoom that would rather consolidate a bill than run a separate mail vendor.
The wider field, by how it bills you.
Feature lists all look the same at this price point. Billing shape is what actually decides the invoice for someone running more than one business, so that is the axis below.
| Destination | Billing | What it's good at | Pick it if |
|---|---|---|---|
| Google Workspace | ~$7 / user / month | Docs, Drive, Meet and the calendar everyone already knows how to use. | You have staff, or you want the office suite as well as the mail. |
| Microsoft 365 Business Basic | ~$7 / user / month | Outlook, Teams and the Office apps; the closest thing to WorkMail's Exchange behaviour. | You came to WorkMail from Exchange and want to go back to it. |
| Zoho Mail | from ~$1 / user / month | AWS's own first-named alternative; per-user mailboxes at the lowest credible price. | You need several people's mailboxes and the budget is the binding constraint. |
| Migadu · Purelymail | $19 / yr · $10 / yr, flat | Unlimited domains for the price of a sandwich, if you bring your own IMAP client. | You are comfortable in Thunderbird or mutt and want the cheapest possible bill. |
| Folio | per operator, never per seat | Every domain in one inbox, replies auto-sent from the domain the message arrived on, per-domain DKIM generated at bind time, and an IMAP import that reads your WorkMail mailbox for you. | You are one person running several businesses, and WorkMail's per-user bill never matched how you actually work. |
Prices are each vendor's own list price, checked 15 August 2026. We publish this table and we are not the cheapest row on it — Migadu and Purelymail are, by a wide margin, and if you are happy in a desktop IMAP client they are the better buy. What the gap pays for is one inbox across every domain instead of one account per domain, a reply-From chosen automatically by the domain the message arrived on, and per-domain DKIM generated when the domain is bound. Folio's own pricing is on the pricing page, from $3.50 a month.
Working backwards from the AWS date
The real deadline is earlier.
You want the move finished while the old mailbox still opens. Anything you discover missing after 31 March 2027 is not recoverable from anywhere, because the source is gone.
30 April 2026
Closed to new customers
Already passed. If you are on WorkMail today you are in the group that has to move.
By 31 December 2026
Import and cut over
Leaves a full quarter of overlap while WorkMail still works, so anything you find missing is recoverable from the source rather than from a backup.
By 28 February 2027
Export what IMAP can't carry
Calendars, contacts and any compliance archive, via AWS's mailbox export guide. These do not travel over IMAP and there is no second chance after the shutdown.
31 March 2027
WorkMail ends
AWS states you will no longer be able to use Amazon WorkMail or reach its console. Nothing left behind is retrievable after this date.
Before you commit to this path
What doesn't come with you.
WorkMail is Exchange-style groupware for organisations. Folio is one inbox for one operator. Some of what WorkMail did for you has no equivalent here, and it is cheaper for both of us if you find that out now.
- Calendars and contacts
- IMAP carries mail and attachments, not calendar or address-book data. Export them from the WorkMail console before the shutdown. Folio has its own calendar, but it does not import WorkMail's.
- Staff mailboxes
- Folio is single-operator: one account, one person, many domains. If other people need their own mailbox on your domain, Folio is the wrong destination today — Zoho Mail, Google Workspace or Microsoft 365 are the honest answers.
- Shared mailboxes and distribution groups
- WorkMail's group and resource mailboxes have no equivalent. A catch-all alias covers some of what a distribution list was doing; it does not cover several people reading one queue.
- Exchange ActiveSync and MAPI clients
- Folio is a web app with IMAP-style semantics, not an Exchange server. Outlook profiles bound to WorkMail over ActiveSync will not transfer.
- Journaling, retention and legal hold
- If you are under a retention obligation, export from WorkMail while it still exists and keep that archive somewhere that meets the obligation. Do not treat any migration as your compliance copy.
Export anything in that list from WorkMail while it still exists — AWS documents the procedure in its mailbox export guide.
The part that isn't manual
Connect once. Folio reads the mailbox.
After signup, open Migrate from AWS WorkMail from your dashboard, enter your WorkMail address and an IMAP password, and Folio imports your historical mail as a background job — dedupe means a re-run never creates copies, and you can check progress or walk away and come back. Nothing is ever exported by hand.
The credential is used once, over an IMAPS (TLS) connection on port 993, then discarded — never written to a database or a log, and never held past the import job. Details on Folio's trust center →
Is this migration right for you?
- You need your mail moved. The import brings over your messages and their attachments. Calendars and contacts aren't carried over IMAP — export those from the WorkMail console separately.
- One mailbox at a time. Run it once per mailbox, each with its own WorkMail address and password. Ideal for a solo operator or a few inboxes, not a bulk org-wide migration in a single pass.
- Your WorkMail region is supported. Pick it below — the eight common regions are covered.
- You can get an IMAP password. If your organization uses SSO, generate an app-specific password in the WorkMail management console.
- You'd rather not wait until 2027. Support ends 31 March 2027; moving now leaves plenty of room to check everything landed.
- You want a permanent inbox, not a temporary one. This is a full mailbox migration. If you actually just need a disposable address for one signup or a single thread, Emcognito handles that instead, free — no need to move anything.
New to DNS? Start here
DNS is just the internet's phone book — it's how "yourdomain.com" tells the world where to send things. An MX record is the one line in that phone book that says "deliver mail here." A TXT record is a small text stamp that proves you're allowed to send mail as your domain, so spam filters trust it. Below, you're only ever touching those mail-routing lines — not your website, not your files, nothing else on the domain changes.
If any of this still feels unfamiliar once you're in your registrar's dashboard, the record cards below are built to be copy-pasted exactly as shown — you don't need to understand DNS to get it right, just to paste carefully.
Preflight · before the DNS cutover
Lower the TTL.
The cutover itself takes seconds — remove one MX row, keep the other. The slow part is DNS propagation, capped by however long resolvers cache your current MX. Give yourself rollback insurance before you touch anything else.
- i Open your registrar (Route 53). Find the MX record for
your-domain.com. - iiLower its TTL to
300. Save. - iiiWait an hour, then continue to Stage I — or start the mail import in the meantime.
Stage I · no downtime · safe at any time
Add Folio's three records.
Publish these alongside your existing WorkMail records. Mail keeps flowing through WorkMail; nothing changes yet.
№ 01MX - Host
- your-domain.com
- Value
- 10 inbound.wm.emcognito.com
Folio's inbound MTA becomes the domain's mail receiver. Priority 10 — no backup record needed.
№ 02TXT - Host
- your-domain.com
- Value
- v=spf1 include:emcognito.com ~all
SPF authorizes Folio's outbound IPs. DMARC below is what actually enforces alignment.
№ 03TXT - Host
- _dmarc.your-domain.com
- Value
- v=DMARC1; p=reject; sp=reject; adkim=s; aspf=r; rua=mailto:dmarc-rua@your-domain.com
Strict DKIM-aligned DMARC. Reports flow to your own dmarc-rua@ address, a receive-only mailbox Folio manages — don't add another _dmarc record.
Hosted zones → your domain → Create record. Route 53 is also where most WorkMail organizations already keep their MX — look for a record with a WorkMail-managed comment before deleting it.
Two more records — per-domain DKIM and SES verification — are account-specific and get generated when you sign up. The in-app domain wizard hands you those values in the same place you pasted these.
Stage II · the cutover · about five minutes
Remove WorkMail's MX.
Folio's MX sits inert until WorkMail's row is gone. AWS WorkMail's documented inbound format is 10 inbound-smtp.<region>.amazonaws.com — confirm the exact row in your own DNS panel before deleting; the region picker above fills in the expected value for reference.
your-domain.com- 10 inbound-smtp.us-east-1.amazonaws.com
The MX added in Stage I is now the only one on your-domain.com. New mail begins arriving in Folio as resolvers refresh within the TTL window from Stage 0.
Open the first letter
Bring your-domain.com
home.
Sign up, connect WorkMail for the automatic import, and publish the DNS records above in whichever order suits you — both finish on their own timeline, and neither blocks the other.
WorkMail billed per mailbox. Folio is flat — every domain you own, one price, from $3.50/mo · full pricing →
No card needed. The first domain you bind and the first 100 sends are free.
Common questions
Questions WorkMail switchers ask.
What are the alternatives to AWS WorkMail?
- AWS's own end-of-support notice names three: Zoho Mail, Kopano Cloud and Zoom Mail. In practice most teams leaving WorkMail land on Google Workspace or Microsoft 365, both about $7 per user per month, because they need mailboxes for staff and an office suite alongside. Folio is a narrower answer: single-operator, priced per operator rather than per seat, and built for one person running several domains from one inbox. If you need mailboxes for other people, pick one of the others — that is not what Folio does.
What happens on 31 March 2027 if I do nothing?
- AWS states that after 31 March 2027 you will no longer be able to use Amazon WorkMail or access its console. Mail stops being delivered and stored mail stops being reachable. There is no stated grace period, so anything you have not exported or migrated by then is gone. WorkMail has been closed to new customers since 30 April 2026, so every remaining account is in the group that has to move.
Is AWS WorkMail being discontinued, or just deprecated?
- Discontinued. AWS is ending support entirely on 31 March 2027 rather than freezing the feature set — the service itself stops. This is not a version deprecation you can sit out.
Does Folio really import my mail automatically, or do I still have to export it myself?
- Folio connects directly to your WorkMail mailbox over IMAP and pulls every message itself — you don't export a file or upload anything. You enter your WorkMail address and an IMAP-capable password once, Folio reads your folders, and the import runs as a background job you can check on.
Is my WorkMail password stored anywhere?
- No. It's used once, to open the IMAP connection for the import, and is never written to a database, a log, or anywhere else. If the import needs to be re-run later, you re-enter it — nothing persists between sessions.
Will mail bounce during the DNS cutover?
- No, if you follow the overlap plan below: lower your MX TTL first, publish Folio's records alongside WorkMail's, then remove WorkMail's MX. Both mail servers accept inbound mail during the overlap window.
What if my organization requires an app-specific password for IMAP?
- Use it — that's the recommended credential for this import, not your primary WorkMail/SSO password. AWS WorkMail administrators can generate app passwords from the WorkMail management console if IMAP access needs one.
Can I import more than one WorkMail mailbox?
- Yes — run the import once per mailbox. Each mailbox is its own IMAP connection, with its own WorkMail address and password, and each domain still gets its own DNS cutover. It's built for a solo operator or a handful of inboxes, not a bulk admin migration across an entire organization in one pass.
Does Folio move my WorkMail calendar and contacts too?
- Not currently. The import runs over IMAP, which carries mail and its attachments but not calendars or contacts. Export those from the WorkMail console separately before support ends on 31 March 2027 if you need to keep them.
Do I have to commit to the full move before I know it worked?
- No. The import only reads from WorkMail over IMAP — it never deletes or modifies anything there, so your existing mailbox stays exactly as it was. Run the import, check that everything landed correctly in Folio, and only start the DNS cutover once you're satisfied. The two steps are independent; nothing about connecting WorkMail commits you to flipping DNS.
Sources & further reading
- Amazon WorkMail — End of support (retirement timeline)
- Amazon WorkMail — Exporting mailbox content
- Zoho Mail — AWS WorkMail alternative (named by AWS)
- Kopano Cloud — WorkMail migration (named by AWS)
- Zoom Mail — Amazon WorkMail (named by AWS)
- Amazon WorkMail — Verifying domains
- Amazon WorkMail — Inbound email
- Amazon Route 53 — Routing traffic to Amazon WorkMail
- RFC 7208 — Sender Policy Framework (SPF)
- RFC 7489 — DMARC