What should a small business check about its email setup?

A small business may start with one email address and one computer.

At that stage, a personal Gmail or Outlook.com address, or an email account supplied with a website hosting package, may appear to do everything that is needed.

Email arrives. Messages can be sent. Outlook or another mail application works.

As the organisation grows, however, the useful question becomes broader:

Is the email setup still suitable for the way the business now works?

Email may now be used across several computers and phones. Contacts may be important business information. Calendars may contain customer appointments, meetings or deadlines. More than one person may need access to a shared address. People may join or leave the organisation.

A setup that still sends and receives email successfully does not necessarily tell you:

    • who ultimately controls the account
    • where contacts and calendars are stored
    • whether they synchronise between devices
    • what happens when another person needs access
    • how an account can be recovered
    • what happens when somebody leaves
    • whether important information is independently backed up

This guide explains the main areas a small business should understand and review.

Personal email accounts and business email

Some small businesses begin by using an address such as:

[email protected]

or:

[email protected]

or an older Hotmail address that gradually became the main business contact.

That does not automatically make the account insecure or unusable.

The more important issue is how the account is owned, administered and recovered.

A personal account is normally centred on an individual account holder. Recovery information, authentication methods and access may therefore depend heavily on that person.

For a sole trader, that may be entirely manageable.

For an organisation with several people, changing responsibilities or business-critical correspondence, the arrangement may need more structure.

Questions worth asking include:

    • Who owns the account?
    • Who controls the recovery email address and telephone number?
    • Is more than one authorised person able to recover access if necessary?
    • Is the address tied permanently to one individual?
    • What would happen if that person were unexpectedly unavailable?

The purpose is not to say that every personal email account must immediately be replaced. It is to understand whether an arrangement created for one person still fits the organisation using it today.

Why using your own domain matters

A business may also use an address based on its own domain, for example:

[email protected]

or:

[email protected]

This separates the organisation’s public email identity from a free consumer email address.

More importantly, control of the domain allows the organisation to decide which email service should handle mail for that address.

The email provider can therefore change in the future without necessarily changing the public email address used by customers and suppliers.

That becomes increasingly useful when:

    • people join or leave
    • mailboxes need to be reassigned
    • shared addresses are introduced
    • email security records need to be managed
    • the organisation moves between hosting providers
    • Microsoft 365 or Google Workspace is introduced later

Owning the domain does not by itself make email secure, backed up or well managed.

It provides an important layer of organisational control.

What IMAP actually synchronises

This is one of the most common areas of misunderstanding.

IMAP is primarily a protocol for accessing and synchronising email.

A simplified model looks like this:

Mail server

IMAP

Email application

Mail folders and messages

If the same IMAP mailbox is configured on a desktop computer and a phone, messages and folders can normally be accessed from both.

That can make the entire setup appear synchronised.

But IMAP itself does not provide a general synchronisation system for:

    • contacts
    • calendars
    • tasks
    • organisational address books
    • shared calendars
    • other application information

This distinction matters particularly when a hosted domain mailbox has simply been added to Outlook using an IMAP username and password.

The email may be synchronised with the mail server.

The contacts and calendar may be somewhere else entirely.

Where are your contacts and calendars stored?

A useful practical question is:

If this computer disappeared today, where would these contacts and appointments come back from?

The answer depends on the setup.

Contacts or calendars may be stored:

    • in Microsoft 365
    • in Google Workspace
    • in an Outlook.com account
    • in a Google Account
    • in iCloud
    • in another cloud service
    • inside an Outlook data file on one computer
    • in a phone account
    • in a separate application
    • or in a combination of several places

This is why the fact that Outlook shows Mail, Calendar and People in the same application does not prove that all three are stored in the same service.

Outlook is an application capable of presenting information from several different sources.

Understanding where each type of information is stored is particularly important before a computer, phone, account or email platform is replaced.

Does seeing email on several devices mean everything is synchronised?

No.

A common situation may look like this:

Office computer
Email ✓
Contacts ✓
Calendar ✓

Laptop
Email ✓
Contacts ?
Calendar ?

Phone
Email ✓
Contacts ?
Calendar ?

The same mailbox appearing on all three devices demonstrates that the email account is accessible from those devices.

It does not by itself prove that the contacts and appointments shown on one of them are stored centrally or synchronised to the others.

This can become visible when:

    • a new computer is installed
    • Outlook is reconfigured
    • a phone is replaced
    • an Outlook profile is recreated
    • a person begins working from home
    • another member of staff needs access

What previously looked like one integrated system may turn out to be several separate storage locations.

What happens when more people need access?

An arrangement designed for one person may become awkward when two or three people need to work with the same business address.

Sharing one username and password between several people does not provide clear individual access or accountability and is generally not a good way to manage a shared business mailbox.

Business platforms can provide more deliberate ways to delegate access.

Microsoft 365, for example, can use shared mailboxes and permissions so authorised people can work with addresses such as accounts@, support@ or reception@ through their own accounts.

Google Workspace also provides organisational sharing and delegated access options.

The wider principle is more important than either product:

Shared business information should have intentional ownership and access.

Who controls the account if somebody leaves?

Email arrangements should also survive staff changes.

Suppose an important customer relationship is associated with one person’s mailbox.

Useful questions include:

    • Can the organisation retain the necessary correspondence?
    • Can authorised colleagues obtain appropriate access?
    • Can future messages be redirected appropriately?
    • Who owns shared contacts?
    • Where are customer appointments stored?
    • Can access be removed without disrupting other people?
    • Can the business recover the account without relying on the departing person?

These questions become harder when business information has gradually accumulated inside personal accounts or local computer profiles.

They are easier when accounts, permissions and ownership have been designed around the organisation.

Is email provider storage the same as backup?

Not necessarily.

This distinction is important.

An email provider may have resilient infrastructure, replicated storage, deleted-item retention or other recovery features.

Those facilities can be useful.

But they are not automatically the same as an independent backup designed around the organisation’s own recovery requirements.

The useful questions are:

    • What information is actually protected?
    • How long is deleted information retained?
    • Can an earlier or deleted item be recovered?
    • What happens after retention expires?
    • Are contacts included?
    • Are calendars included?
    • Are shared mailboxes included?
    • Can the organisation perform the required restore?
    • Has recovery actually been tested?

This follows the same principle explained in our Cloud Storage vs Backup: Why Sync Is Not Backup guide: synchronisation, retention and an independent recovery copy perform different jobs.

What should be included in an email backup?

The answer depends on what the organisation relies upon.

For one business, email may be the main concern.

For another, important information may include:

    • email messages
    • mailbox folders
    • contacts
    • calendars and appointments
    • shared mailboxes
    • shared calendars
    • OneDrive or Google Drive information
    • SharePoint data
    • other cloud application information

A backup arrangement should therefore begin with the information the business would actually need to recover.

A backup that protects email but omits an essential shared calendar may not meet the organisation’s real recovery requirement.

Likewise, a backup service that reports successful jobs still needs appropriate restore testing.

When Microsoft 365 or Google Workspace may make more sense

The purpose of this guide is not to say that every business must move to Microsoft 365 or Google Workspace.

A single-person organisation with modest requirements may be comfortable with a simpler arrangement.

But as requirements grow, an organisational platform may provide a more coherent model for:

    • individual business accounts
    • administrator control
    • domain-based email
    • shared mailboxes or delegated access
    • calendars
    • contacts
    • collaboration
    • access management
    • security policies
    • account lifecycle management

The appropriate platform still depends on the organisation.

A change should solve a real requirement rather than being made simply because one platform is considered more sophisticated.

Your Microsoft 365 setup still needs to be reviewed

Moving to Microsoft 365 does not remove the need to think about security, administration and recovery.

A Microsoft 365 environment may contain business email, files, identities, applications, sharing and access from several devices.

Administrator access, multi-factor authentication, application permissions, device management, email-domain protection, backup and monitoring may all need attention.

For a more detailed explanation, see our Microsoft 365 Tenant Security for Small Businesses guide.

Email security also needs attention

Where an organisation uses its own domain, email delivery and identity controls should also be considered.

These may include:

    • SPF
    • DKIM
    • DMARC
    • appropriate mailbox authentication
    • anti-phishing and filtering controls
    • MTA-STS and TLS reporting where justified

These technologies solve different problems from backup.

A backup helps with recovery.

Email authentication helps receiving systems assess whether messages claiming to come from a domain are authorised.

Transport-security controls address another part of mail delivery.

No single setting performs all of these jobs.

For further detail, see our Email Validation and Security and What Is MTA-STS? Email Transport Security Explained guides.

A practical small-business email review

A better starting point is to understand the environment you already have.

Check:

    1. Which email addresses are being used for business?
    2. Does the organisation control its own email domain?
    3. Who owns and can recover each important account?
    4. Where is the email stored?
    5. Where are contacts stored?
    6. Where are calendars and appointments stored?
    7. Do those items synchronise between the devices where they are needed?
    8. Are passwords being shared between people?
    9. What happens when somebody joins or leaves?
    10. Which information would need to be recovered after deletion, account loss or another problem?
    11. Is that information independently backed up?
    12. Has recovery been tested?
    13. Are the domain and mailbox security settings still appropriate?

Not every small organisation needs the same answer.

The important point is to know where the information lives, who controls it, how it is shared and how it could be recovered.

Email, contacts and calendars can begin as simple services and gradually become part of the organisation’s wider working infrastructure.

If they are important to day-to-day work, it is useful to understand where the information is stored, who controls it, what synchronises between devices and how the information could be recovered.

Evening Computing can help with email, Microsoft 365, Google Workspace, cloud services, backup arrangements and wider IT support where these systems need to be reviewed or changed.

For related guidance, see our Microsoft 365 Tenant Security for Small Businesses, Cloud Storage vs Backup: Why Sync Is Not Backup and Email Validation and Security guides.

Further Guidance and Support

This guide forms part of a broader layered security approach. For structured guidance on security and resilience planning, see our Security and Resilience page.

For information about practical implementation and ongoing support, you can review our IT services and local IT support coverage across London, Hertfordshire, and Essex.

Author
Elías Sánchez
IT Support Consultant
Evening Computing

This guide was prepared by Elías Sánchez with research and drafting assistance from AI tools. All technical content has been reviewed and adapted for clarity and accuracy.

Last reviewed
25 August 2026