Most email migrations that go wrong were already in trouble before the first mailbox moved: nobody had the DNS login, a license tier was wrong, or a scanner that sends mail was forgotten. Work through this list before you set a cutover date. Click any item to check it off. Your progress is saved in this browser.
Access and ownership
- You can sign in to the DNS host for your domain, and you know who else has access
- You have global admin on the destination Microsoft 365 tenant, with an account that isn't one person's mailbox
- You have admin access to the source (GoDaddy, Google Workspace, Exchange server, or IMAP host)
- You know the renewal or cancellation date for the current email service, and you won't cancel before the migration is finished
- If the source is GoDaddy Microsoft 365, you've confirmed whether the domain is federated (here's why it matters)
Licensing
- Every user who needs a mailbox has a license assigned in the destination tenant
- You've chosen the right tier: Business Basic (web/mobile apps), Standard (desktop apps), or Premium (adds Intune and advanced security)
- Shared mailboxes are identified. They don't need a license under 50 GB unless they need archiving.
- Former employees' mailboxes have a plan: migrate, convert to shared, or export and delete
Mailbox data
- You have a list of every mailbox, alias, and distribution list, with owners
- You know the total mailbox size and the largest single mailbox
- Any mailbox over 50 GB has a plan (archive, a higher license, or cleanup)
- PST files on local PCs are found, and you've decided whether to import them
- Shared calendars, delegates, and "send as" permissions are documented
DNS and mail flow
- Current MX, SPF, autodiscover, DKIM, and DMARC records are exported and saved
- TTLs are lowered to 300–600 seconds at least 48 hours before cutover
- Every system that sends mail as your domain is listed: website forms, scanners, CRM, invoicing, newsletters
- Devices that send through SMTP with a username and password (copiers, old apps) have a plan, since basic auth is being retired
Devices and users
- You know which users read mail on phones, and which apps they use
- You know who uses Outlook desktop vs web vs Mac Mail
- Signatures, rules, and filters have been flagged to users as things they may need to recreate
- One or two pilot users have agreed to go first and report honestly
Communication and timing
- A cutover date is set at a quiet time for the business, not during month-end or a big launch
- Users have received a "what's changing" email at least a week ahead
- Users will receive day-of instructions: what to expect Monday morning, and who to call
- Someone is on call the first business morning after cutover
- You have a rollback plan if something serious goes wrong
Security, day one
- MFA will be required from the first sign-in on the new platform
- Legacy authentication will be blocked
- SPF, DKIM, and DMARC are ready to publish (setup guide)