[{"data":1,"prerenderedAt":174},["ShallowReactive",2],{"seo-verification":3,"blog-aws-workmail-eol-migrate-mailcow-vps-en":6},{"google":4,"bing":5},"EycwPY2XMyTkVzas3n1ygeNJFGAH513qrMjfDljzsMQ","",{"key":7,"data":8},"blog-aws-workmail-eol-migrate-mailcow-vps-en",{"id":9,"slug":10,"slugs":11,"title":15,"excerpt":16,"readTime":17,"views":18,"isPinned":19,"publishedAt":20,"updatedAt":21,"category":22,"categories":27,"featuredImage":29,"bgImage":30,"posterImage":31,"relatedSolution":29,"intro":32,"sections":33,"ctaTitle":119,"ctaBody":120,"ctaButton":121,"ctaUrl":122,"relatedPosts":123},392,"aws-workmail-eol-migrate-mailcow-vps",{"fr":12,"en":10,"ar":13,"es":14},"aws-workmail-eol-migrer-mailcow-vps","إغلاق-aws-workmail-الانتقال-الى-mailcow-vps","aws-workmail-cierre-migrar-mailcow-vps","AWS WorkMail EOL: migrate to self-hosted Mailcow on VPS","AWS WorkMail shuts down on March 31, 2027. Full guide: S3 export, IMAP migration with imapsync and DNS cutover to self-hosted Mailcow.",10,0,false,"2026-09-27T00:00:00+00:00","2026-09-29T14:40:42+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},11,"Business Email","emails","bg-cyan-500\u002F10 text-cyan-400",[28],{"id":23,"name":24,"slug":25,"color":26,"icon":25},null,"\u002Fblog\u002Fcovers\u002Fbg.svg","\u002Fblog\u002Fcovers\u002Faws-workmail-eol-migrer-mailcow-vps-poster.svg","Amazon has made it official: AWS WorkMail stopped accepting new customers on April 30, 2026, and all existing accounts will be deleted on March 31, 2027. If you have not yet migrated your email, you have less than six months to export your data, update your DNS records and move your users. This guide focuses on what the official announcement does not detail — how to actually recover your emails, transfer them to a self-hosted Mailcow server, and verify that deliverability is preserved before cutting off AWS.",[34,38,41,44,57,79,91,106,109,113,116],{"type":35,"title":36,"body":37},"h2","AWS WorkMail EOL — timeline and what it means","AWS published the end-of-support notice on the official WorkMail documentation page. Two dates are irrevocable: **April 30, 2026** — no new customer sign-ups; **March 31, 2027** — all accounts, mailboxes, calendars and contacts are deleted, with no recovery possible after that date.\n\nIn practice, WorkMail resources become inaccessible on April 1, 2027: the AWS console, APIs, IMAP clients and Exchange ActiveSync connectors all stop responding simultaneously. AWS has not announced any extension or post-date read-only mode. **Anything not exported before March 31, 2027 is permanently lost.**\n\nThe urgency depends on your mailbox volume: a 10 GB mailbox can take several hours to export to S3, and the imapsync IMAP migration takes time proportional to the number of messages. Starting the migration three months before the deadline is a reasonable minimum. Ideally, the DNS cutover should be completed before the end of January 2027, leaving enough time to monitor deliverability and fix any issues before the definitive deletion.",{"type":35,"title":39,"body":40},"Why Mailcow rather than Stalwart or another alternative","AWS itself recommends Kopano Cloud, Zoho Mail and Zoom Mail as alternatives. These solutions remain SaaS — you switch providers without regaining control.\n\nIf you want an email infrastructure you fully control, Mailcow is the most proven option for migrating from a hosted email service. Its Docker Compose stack combines Postfix, Dovecot, Rspamd and SOGo in a unified administration interface. IMAP migration is well documented, the community is active, and native IMAP inbound support makes importing with imapsync straightforward.\n\nStalwart is a serious alternative (see the dedicated article), but its single-binary architecture is better suited to a fresh installation than to a migration from WorkMail — support for importing existing IMAP mailboxes is less mature at the time of writing. For a WorkMail migration, Mailcow is the pragmatic choice.",{"type":35,"title":42,"body":43},"Prerequisites before you begin","Three resources are required before starting the migration:\n\n**VPS with at least 6 GB of RAM.** The Mailcow stack (Postfix, Dovecot, Rspamd, MariaDB, Redis, ClamAV, SOGo and the nginx proxy) consumes around 3 to 4 GB under normal load. With 6 GB, you have a comfortable margin for imapsync and load spikes during migration.\n\n**Administrator access to the AWS WorkMail console.** Mailbox export goes through the AWS API — you need sufficient IAM rights to create an export role, access S3 and trigger export jobs via the CLI.\n\n**A domain name with DNS access.** The DNS cutover (MX, SPF, DKIM, DMARC records) is the final step — without access to your DNS zone, you cannot redirect inbound mail to Mailcow.",{"type":45,"title":46,"items":47},"ul","Detailed prerequisites list",[48,49,50,51,52,53,54,55,56],"64-bit Linux VPS (Debian 12 or Ubuntu 22.04 recommended), minimum 6 GB RAM \u002F 2 vCPU \u002F 40 GB storage.","Dedicated IP with PTR (reverse DNS) configured to match the mail server hostname.","Outbound port 25 unblocked by your hosting provider — check before ordering.","Ports 25, 465, 587, 993 and 143 open in the VPS firewall.","AWS IAM access with `workmail:StartMailboxExportJob`, `s3:PutObject` and `kms:GenerateDataKey` rights.","A private S3 bucket in the same AWS region as your WorkMail organisation.","A symmetric KMS key in the same region (required by the WorkMail export API).","DNS access to the domain to modify MX, SPF, DKIM and DMARC.","Docker and Docker Compose installed on the target VPS.",{"type":58,"title":59,"steps":60},"steps","Exporting your AWS WorkMail data",[61,64,67,70,73,76],{"title":62,"body":63},"Create the IAM role and export policies","The WorkMail export requires a dedicated IAM role. Create two local JSON files:\n\n`mailbox-export-trust-policy.json` (trust policy for WorkMail): `{ \"Version\": \"2012-10-17\", \"Statement\": [{ \"Sid\": \"\", \"Effect\": \"Allow\", \"Principal\": { \"Service\": \"export.workmail.amazonaws.com\" }, \"Action\": \"sts:AssumeRole\", \"Condition\": { \"StringEquals\": { \"aws:SourceAccount\": \"YOUR-ACCOUNT-ID\" } } }] }`\n\n`mailbox-export-policy.json` (S3 and KMS rights): see the official documentation for the complete JSON with your bucket and KMS key ARNs.\n\nCreate the role via AWS CLI:\n`aws iam create-role --role-name WorkmailMailboxExportRole --assume-role-policy-document file:\u002F\u002Fmailbox-export-trust-policy.json`\n`aws iam put-role-policy --role-name WorkmailMailboxExportRole --policy-name MailboxExport --policy-document file:\u002F\u002Fmailbox-export-policy.json`",{"title":65,"body":66},"Retrieve organisation and user identifiers","The export API requires the WorkMail organisation ID and entity ID for each user. Retrieve them from the AWS WorkMail console under **Organizations → your org → Users**, or via CLI:\n\n`aws workmail list-organizations`\n\n`aws workmail list-users --organization-id m-XXXXXXXXXXXX`\n\nNote the `OrganizationId` (format `m-xxxxx`) and the `UserId` of each mailbox to export.",{"title":68,"body":69},"Launch the S3 export job","Trigger one export job per mailbox:\n\n`aws workmail start-mailbox-export-job --organization-id m-XXXXXXXXXXXX --entity-id S-1-1-11-XXXXXXXXXX --kms-key-arn arn:aws:kms:us-east-1:ACCOUNT:key\u002FKEY-ID --role-arn arn:aws:iam::ACCOUNT:role\u002FWorkmailMailboxExportRole --s3-bucket-name your-bucket --s3-prefix exports\u002Fuser1\u002F`\n\nThe API supports up to 10 concurrent export jobs per organisation. For large organisations, launch exports in batches of 10 and wait for each batch to complete.",{"title":71,"body":72},"Monitor export job status","Check progress with:\n\n`aws workmail list-mailbox-export-jobs --organization-id m-XXXXXXXXXXXX`\n\nOr for a specific job:\n\n`aws workmail describe-mailbox-export-job --organization-id m-XXXXXXXXXXXX --job-id JOB-ID`\n\nWhen the status changes to `COMPLETED`, the `.zip` file is available in S3. The output log shows `totalMessages`, `totalBytes` and `sha384Hash` for integrity verification.",{"title":74,"body":75},"Download and verify exported files","Download the archives from S3:\n\n`aws s3 sync s3:\u002F\u002Fyour-bucket\u002Fexports\u002F .\u002Fworkmail-exports\u002F`\n\nVerify the integrity of the downloaded archives. Each `.zip` contains emails in MIME format. Check that the file count matches the `totalMessages` from the export log:\n\n`unzip -l workmail-exports\u002Fuser1\u002F*.zip | tail -1`\n\nKMS encryption is transparent on the AWS side — files downloaded by a user with access to the KMS key are decrypted automatically.",{"title":77,"body":78},"Extract .eml files for imapsync","imapsync works IMAP-to-IMAP — it does not directly import `.zip` or `.eml` files from disk. The recommended approach is to configure imapsync to read directly from the WorkMail IMAP server before access is cut off, rather than going through S3 archives.\n\nThe S3 archives serve as a safety backup and for mailboxes that are no longer accessible via IMAP. To process `.eml` files as a last resort, a temporary local Dovecot server can expose them over IMAP for imapsync.",{"type":58,"title":80,"steps":81},"Installing Mailcow on VPS",[82,85,88],{"title":83,"body":84},"Prepare the VPS and configure the hostname","Set an FQDN hostname consistent with the future PTR record:\n\n`hostnamectl set-hostname mail.yourdomain.com`\n\nVerify that `hostname -f` returns the full FQDN. Configure the PTR for the VPS IP from your hosting provider's control panel — this PTR must exactly match the hostname.",{"title":86,"body":87},"Clone Mailcow and run the installer","Refer to the dedicated article **Host an email server on VPS with Mailcow** for the full installation. In summary:\n\n`git clone https:\u002F\u002Fgithub.com\u002Fmailcow\u002Fmailcow-dockerized \u002Fopt\u002Fmailcow-dockerized`\n`cd \u002Fopt\u002Fmailcow-dockerized && .\u002Fgenerate_config.sh`\n`docker compose pull && docker compose up -d`\n\nThe administration interface is available at `https:\u002F\u002Fmail.yourdomain.com` after DNS propagation.",{"title":89,"body":90},"Create domains and accounts in Mailcow","In the Mailcow interface (Configuration → Mail Setup), add the domain and create an account for each WorkMail user to migrate. Addresses must be identical to those in WorkMail so imapsync can match mailboxes.\n\nDo not change the MX records yet — Mailcow can accept IMAP connections without being the active MX, which allows migration before the DNS cutover.",{"type":58,"title":92,"steps":93},"Migrating emails with imapsync",[94,97,100,103],{"title":95,"body":96},"Install imapsync on the Mailcow VPS","On Debian\u002FUbuntu:\n\n`apt-get install -y imapsync`\n\nOr from the official repository for the latest version:\n\n`curl -L https:\u002F\u002Fimapsync.lamiral.info\u002FINSTALL.d\u002FINSTALL.Debian.txt | bash`\n\nVerify the installation: `imapsync --version`",{"title":98,"body":99},"Migrate a WorkMail mailbox to Mailcow","The AWS WorkMail IMAP server in us-east-1 is `imap.mail.us-east-1.awsapps.com` (port 993, SSL). Adjust the region if your organisation is in eu-west-1 (`imap.mail.eu-west-1.awsapps.com`) or us-west-2.\n\n`imapsync \\\n  --host1 imap.mail.us-east-1.awsapps.com --ssl1 --port1 993 \\\n  --user1 user@yourdomain.com --password1 'WorkMailPassword' \\\n  --host2 mail.yourdomain.com --ssl2 --port2 993 \\\n  --user2 user@yourdomain.com --password2 'MailcowPassword' \\\n  --automap --skipcrossduplicates --useuid`\n\nThe `--automap` option automatically maps system folders (Sent, Drafts, Trash) between the two servers. `--skipcrossduplicates` avoids duplicates if you re-run the migration. `--useuid` uses IMAP UIDs for accurate progress tracking.",{"title":101,"body":102},"Migrate all mailboxes in parallel","For organisations with multiple users, run migrations in parallel with a script:\n\n`while IFS=: read -r user pass_wm pass_mc; do\n  imapsync \\\n    --host1 imap.mail.us-east-1.awsapps.com --ssl1 --port1 993 \\\n    --user1 \"$user\" --password1 \"$pass_wm\" \\\n    --host2 mail.yourdomain.com --ssl2 --port2 993 \\\n    --user2 \"$user\" --password2 \"$pass_mc\" \\\n    --automap --skipcrossduplicates --useuid \\\n    --logfile \"\u002Fvar\u002Flog\u002Fimapsync-$user.log\" &\ndone \u003C users.csv`\n\nLimit to 4 to 6 simultaneous migrations to avoid saturating bandwidth. Monitor logs in `\u002Fvar\u002Flog\u002Fimapsync-*.log`.",{"title":104,"body":105},"Run a final synchronisation pass","While users continue using WorkMail, re-run imapsync one last time just before the DNS cutover to sync emails received since the first migration:\n\n`imapsync \\\n  --host1 imap.mail.us-east-1.awsapps.com --ssl1 --port1 993 \\\n  --user1 user@yourdomain.com --password1 'WorkMailPassword' \\\n  --host2 mail.yourdomain.com --ssl2 --port2 993 \\\n  --user2 user@yourdomain.com --password2 'MailcowPassword' \\\n  --automap --skipcrossduplicates --useuid --delete2duplicates`\n\nThanks to `--useuid`, imapsync only transfers messages absent from Mailcow.",{"type":35,"title":107,"body":108},"DNS cutover — MX, SPF, DKIM, DMARC","Once the IMAP migration is complete and verified, the DNS cutover redirects inbound mail to Mailcow. **Do not cut over before verifying deliverability** (see the next section).\n\n**Step 1 — MX record.** Replace the existing MX entry (pointing to WorkMail, e.g. `inbound-smtp.us-east-1.amazonaws.com`) with your Mailcow server:\n\n`yourdomain.com. MX 10 mail.yourdomain.com.`\n\nVerify propagation: `dig MX yourdomain.com +short`\n\n**Step 2 — SPF.** Remove the WorkMail authorisation (`include:amazonses.com` or similar) and authorise your VPS:\n\n`yourdomain.com. TXT \"v=spf1 mx a:mail.yourdomain.com -all\"`\n\nVerify: `dig TXT yourdomain.com +short | grep spf`\n\n**Step 3 — DKIM.** Mailcow generates DKIM keys from the interface (Configuration → Configuration & Details → ARC\u002FDKIM Keys). Copy the generated TXT record into your DNS:\n\n`nslookup -type=TXT dkim._domainkey.yourdomain.com`\n\n**Step 4 — DMARC.** Update the DMARC policy. If a policy existed for WorkMail, replace the `rua` address and keep `p=quarantine` or `p=reject` if already in place:\n\n`_dmarc.yourdomain.com. TXT \"v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; pct=100\"`\n\nVerify: `dig TXT _dmarc.yourdomain.com +short`\n\nReduce the TTL of all these records to 300 seconds one hour before the cutover to speed up propagation.",{"type":110,"title":111,"body":112},"tip","Test deliverability before cutting AWS","Before changing the MX, send an email from Mailcow (via SOGo webmail or a client configured on port 587) and check the score on \u003Ca href=\"https:\u002F\u002Fwww.mail-tester.com\">mail-tester.com\u003C\u002Fa> — a score of 9\u002F10 or above is the acceptable threshold for production.\n\nAlso verify with `swaks` from the VPS itself:\n\n`swaks --to test@gmail.com --from contact@yourdomain.com --server mail.yourdomain.com --port 587 --auth LOGIN --auth-user contact@yourdomain.com --tls`\n\nInspect the headers of the received message — the `Authentication-Results` header must show `spf=pass`, `dkim=pass` and `dmarc=pass`. If any of the three is missing or failing, **do not cut the MX** — fix the failing DNS record first.\n\nAlso check that the VPS IP is not listed in a reputation database with `dig +short TXT \u003Creversed-ip>.zen.spamhaus.org` (an empty response means a clean IP).",{"type":35,"title":114,"body":115},"Troubleshooting — common imapsync and Mailcow errors","**`IMAP Command 'LOGIN' failed: 535 5.7.3 Authentication unsuccessful`** — WorkMail credentials are rejected. Verify that the password is the application password generated in the WorkMail console (not the SSO\u002Ffederated password). If your organisation uses Active Directory or an external identity provider, IMAP credentials must be configured separately in WorkMail.\n\n**`SSL connect attempt failed error:14090086`** — Incompatible TLS version or expired certificate on one of the servers. Add `--ssl1 --tls1` to force TLS 1.2, or `--notls1 --ssl1` to force direct SSL. Check the Mailcow certificate with `openssl s_client -connect mail.yourdomain.com:993`.\n\n**`Can't login to host2... Connection refused on port 993`** — Mailcow is not yet listening on the IMAPS port. Check that all containers are running with `docker compose -f \u002Fopt\u002Fmailcow-dockerized\u002Fdocker-compose.yml ps`. The `dovecot-mailcow` container must be `Up`.\n\n**`Quota exceeded on host2`** — The destination mailbox has reached its quota limit in Mailcow. Increase the quota from the Mailcow interface (Configuration → Mail Setup → Mailboxes) before re-running imapsync.\n\n**Very slow migration or random disconnections** — imapsync can be slowed by network latency between the VPS and AWS servers. Add `--maxbytespersecond 500000` to limit throughput and avoid timeouts. Run imapsync inside a `screen` or `tmux` session to avoid interruptions if the SSH connection drops:\n\n`screen -S migration imapsync ...`",{"type":35,"title":117,"body":118},"Conclusion — act before March 31, 2027","The closure of AWS WorkMail is a final decision. The migration window is short: between DNS propagation, deliverability verification and IMAP migration of large mailboxes, budget one to two weeks of work for a small-to-medium organisation.\n\nThe safest path is the one described here: first export data to S3 (an irreversible backup before any manipulation), migrate emails via imapsync while WorkMail is still active, validate deliverability on Mailcow before cutting over, then switch the MX and deactivate WorkMail accounts.\n\nFor large organisations with dozens of mailboxes and high volumes, plan a coexistence period of two to four weeks where both systems are active, with automatic forwarding of WorkMail messages to Mailcow via a forwarding rule, before the final DNS cutover.","Deploy Mailcow on a reliable VPS","Migrating from AWS WorkMail is an opportunity to regain full control of your email infrastructure. ServOrbit offers VPS with dedicated IP, unblocked port 25 and technical support to help you install and configure Mailcow in production.","View hosting plans","\u002Fhebergement-web",[124,141,158],{"id":125,"slug":126,"slugs":127,"title":131,"excerpt":132,"readTime":133,"views":134,"isPinned":19,"publishedAt":135,"updatedAt":136,"category":137,"categories":138,"featuredImage":29,"bgImage":30,"posterImage":140,"relatedSolution":29},238,"hosting-your-own-email-server-on-a-vps-with-mailcow",{"fr":128,"en":126,"ar":129,"es":130},"heberger-serveur-email-vps-mailcow","استضافة-خادم-البريد-الإلكتروني-على-vps-باستخدام-mailcow","alojar-servidor-correo-vps-mailcow","Hosting Your Own Email Server on a VPS with Mailcow","Deploy Mailcow on a Linux VPS to run your own sovereign email server: installation, deliverability and migration from Google Workspace.",13,2,"2026-08-08T00:00:00+00:00","2026-09-07T11:26:10+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},[139],{"id":23,"name":24,"slug":25,"color":26,"icon":25},"\u002Fblog\u002Fcovers\u002Fheberger-serveur-email-vps-mailcow-poster.svg",{"id":142,"slug":143,"slugs":144,"title":148,"excerpt":149,"readTime":150,"views":151,"isPinned":19,"publishedAt":152,"updatedAt":153,"category":154,"categories":155,"featuredImage":29,"bgImage":30,"posterImage":157,"relatedSolution":29},345,"dmarc-p-quarantine-email-deliverability",{"fr":145,"en":143,"ar":146,"es":147},"dmarc-p-quarantine-email-delivrabilite","dmarc-p-quarantine-email-deliverability-ar","dmarc-p-quarantine-entregabilidad-email","DMARC p=quarantine: stop sending in monitor-only mode","In 2026, Google and Microsoft throttle senders of more than 100 emails\u002Fday stuck on DMARC p=none. SPF, DKIM, DMARC and List-Unsubscribe one-click checklist.",9,1,"2026-09-10T00:00:00+00:00","2026-09-10T13:10:45+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},[156],{"id":23,"name":24,"slug":25,"color":26,"icon":25},"\u002Fblog\u002Fcovers\u002Fdmarc-p-quarantine-email-delivrabilite-poster.svg",{"id":159,"slug":160,"slugs":161,"title":165,"excerpt":166,"readTime":167,"views":168,"isPinned":19,"publishedAt":169,"updatedAt":136,"category":170,"categories":171,"featuredImage":29,"bgImage":30,"posterImage":173,"relatedSolution":29},327,"stalwart-mail-server-smtp-imap-and-jmap-in-a-single-rust-binary",{"fr":162,"en":160,"ar":163,"es":164},"stalwart-mail-server-vps","stalwart-mail-server-على-vps-خادم-بريد-متكامل-بلغة-rust","stalwart-mail-server-smtp-imap-y-jmap-en-un-unico-binario-rust","Stalwart Mail Server: SMTP, IMAP and JMAP in a single Rust binary","Deploy Stalwart Mail Server on a VPS: full email server in Rust, native SPF\u002FDKIM\u002FDMARC, single binary without a complex multi-container Docker stack.",8,6,"2026-09-04T00:00:00+00:00",{"id":23,"name":24,"slug":25,"color":26,"icon":25},[172],{"id":23,"name":24,"slug":25,"color":26,"icon":25},"\u002Fblog\u002Fcovers\u002Fstalwart-mail-server-vps-poster.svg",1790693240190]