Managed Email Services: What a Provider Should Actually Run for You
Most businesses buy email once and never think about it again. A provider sets up Microsoft 365 or Google Workspace, mail flows, and the subject closes. Then a mailbox gets compromised, or a client says your invoices are landing in junk, or somebody deletes a folder and discovers on day 41 that the retention window was 30 days — and it turns out email was never actually being managed at all. It was being hosted.
There is a real difference. This guide sets out what a managed email service should include, what is normally missing, and how to tell the two apart when comparing providers across the GTA.
Hosting Is Not Management
A licence gets you the platform. Management is the ongoing work that keeps it secure, recoverable and trusted by the rest of the internet — and almost none of it happens automatically.
The clearest illustration is the shared-responsibility model both Microsoft and Google operate. They are responsible for the service being available. You are responsible for your data in it: who has access, what leaves, what gets deleted, and what you can recover after the platform's own retention window closes. That last point surprises people regularly, because a deleted-items policy feels like a backup right up to the moment it isn't one.
What Belongs in a Managed Email Service
Identity and access control. Multi-factor authentication on every mailbox — not most, every, including the shared account nobody wants to touch and the executive who finds it inconvenient. Conditional access rules that reflect how your staff actually work. Least-privilege administrative roles instead of four people with global admin because it was easier during setup.
Authentication of your domain. SPF, DKIM and DMARC, configured and taken all the way to enforcement rather than left in the monitoring mode where most implementations stall. This does two jobs at once: it stops attackers spoofing your domain to your own clients, and it materially improves whether your legitimate mail reaches inboxes at all. When we checked the public DNS records of 118 GTA business domains, only 40% were fully protected. Our explainer on SPF, DKIM and DMARC covers what enforcement involves.
Filtering that is tuned, not just switched on. Default anti-spam and anti-phishing policies are a starting point. A managed service reviews quarantine, adjusts policies as attack patterns move, adds impersonation protection for the names attackers actually use — your CEO, your bookkeeper, your largest supplier — and tells you when something got through so the rule can change.
Backup, separate from the platform. Third-party backup of mailboxes, and typically of OneDrive, SharePoint and Teams, held independently of the tenant with a retention period you chose rather than inherited. The number that matters is not the retention policy; it is the date of the last successful test restore. Ask for it. Our cloud backup and disaster recovery guide sets out what a defensible answer looks like.
Monitoring of the mailbox itself. The signals that reveal a compromised account are well known and rarely watched: new forwarding or inbox rules, impossible-travel sign-ins, sudden bulk sending, mass downloads. Someone should be alerted on these around the clock and able to act — disable the account, revoke the sessions, work out what was read. That is the difference between an incident that lasts twenty minutes and one that lasts three weeks and ends in a redirected payment. Managed detection and response is where that coverage lives.
Lifecycle and hygiene. Starters and leavers handled properly, including what happens to a departing employee's mail. Shared mailboxes and distribution lists reviewed rather than accumulating for a decade. Licence counts matched to actual people, which quietly saves real money in businesses with seasonal or contract staff.
Continuity. A plan for what your business does during a platform outage — the answer may legitimately be "we wait", but that should be a decision rather than a discovery.
How to Tell Whether Yours Is Managed
Six questions, none of them technical, all of them answerable by whoever runs your IT today.
Is our domain at DMARC enforcement, and can you show me? Which mailboxes do not have MFA enabled right now? What backs up our email, where does it live, and when was the last test restore? Who is alerted if a mailbox starts forwarding mail externally at 2 a.m., and what do they do? How many people hold global administrator? What happens to a departing employee's mailbox, and who decides?
If the answers arrive with specifics, email is being managed. If they arrive as reassurance, it is being hosted — which may be entirely adequate for a five-person business with no client money moving through the inbox, and is a serious exposure for anyone approving payments by email.
Microsoft 365, Google Workspace, or Something Else
Both major platforms are capable of everything above; they differ in administrative model, licensing and how the security features are packaged. The choice matters far less than whether anyone is doing the work. We published a comparison of the email platforms GTA businesses actually run based on live measurement, if you are choosing or reconsidering.
For businesses already on Microsoft 365, the practical follow-on is configuration rather than migration — our Microsoft 365 security best practices guide covers the settings that do the most work.
Where IT Rapid Support Fits
IT Rapid Support manages email for businesses across the GTA as part of our managed IT service rather than as a separate product: MFA and conditional access, SPF, DKIM and DMARC to enforcement, tuned filtering and impersonation protection, third-party backup with tested restores, and round-the-clock monitoring of the sign-in and mailbox-rule activity that reveals a compromised account. It runs from our head office at 7810 Keele St in Vaughan, with local coverage including managed IT services in Newmarket, IT support in Aurora, IT support in Richmond Hill and managed IT services in Vaughan.
If you cannot answer the six questions above about your own email, call (289) 582-9930 — the DMARC and MFA answers usually take under an hour to establish, and they are where the exposure normally is.
Share this resource

IT Rapid Support Team
Managed IT & Cybersecurity, GTA
IT Rapid Support Team is a security expert with extensive experience in creating security guidelines.
More from this authorRelated Resources
IT Companies in Toronto: Which Type Does Your Business Actually Need?
Toronto IT companies range from break-fix shops to full MSPs and security-focused MSSPs. What each type actually does, what it costs, and how to pick the right fit.
Read moreCybersecurity Services in Toronto: What Your Business Actually Needs in 2026
What cybersecurity services Toronto businesses need in 2026: 24/7 monitoring and MDR, email security, MFA, backups, and how to choose the right provider.
Read more7 Questions to Ask a Vaughan IT Provider Before You Sign
A buyer's checklist for comparing IT providers in Vaughan: what 24/7 really covers, on-site response, what security is included, and how backups get tested.
Read moreNeed Expert Security Advice?
Our team of cybersecurity experts is ready to help you secure your organization. Schedule a free consultation today.
Get in Touch