Buyer Guides & Decision

How to choose an email forwarding provider: 25-point checklist

Score leftover MX, From rewrite, logs, and limits. Brand comes last.

MailerZ editorial · Secuno LLC17 min read

Choose an email forwarding provider with a written checklist, not a homepage gradient. The twenty-five points below cover exclusive MX, Header From handling, leftover MX, logs, catch-all policy, send-as, store window, and the cases where you should walk away. MailerZ is one option in that class: envelope SRS only, Header From never rewritten, not IMAP, not an open relay. Use the list on MailerZ and on everyone else. A vendor that fails leftover MX or From rewrite is a no, even if the free tier is pretty.

25-point checklist for choosing an email forwarding provider
Score the hop, the From, the leftovers, and the proof. Brand comes last.

Quick answer for choose email forwarding provider

Write the twenty-five points. Trial two vendors against the same domain or a lab domain. Score leftover MX, Header From, logs, and limits. Pick the one that fails fewer hard stops.

Do not start with price. A free hop that rewrites From will cost you bank mail. Do not start with a logo. Start with a uniquely titled probe and a resolver listing.

Keep IETF RFC 5321 — Simple Mail Transfer Protocol and IETF RFC 7208 — Sender Policy Framework (SPF) in the ticket. Product pages to compare against: features, pricing, troubleshooting.

User problem and decision criteria

People choose an email forwarding provider the way they choose a VPN: a listicle, a discount, a tweet. Then leftover MX splits their first invoice and they blame 'DNS.'

The real decision is whether you are buying a hop in front of Gmail or accidentally buying a rewrite proxy, a mailbox host, or a campaign sender.

Criteria that matter: exclusive MX discipline, From integrity, catch-all honesty, send-as authorization, store window, and a way to prove a failure.

Criteria that do not matter until the hop works: brand color, a mascot, a lifetime deal, a comparison table from 2023.

If you need IMAP, stop using this checklist. You need a host. If you need a suite, buy a suite. Forwarding checklists cannot save the wrong class.

If security review asked for SOC 2, ask the vendor for the report or accept that many forwarders, including MailerZ, will say no. Do not launder a missing badge.

What you are actually buying

A forwarder accepts mail for your domain at MX, optionally stores a short window, and hands the message to a destination mailbox. Some also accept authenticated SMTP so you can send-as the domain.

The envelope sender may be rewritten so bounces return to the hop. That is SRS. It is not a license to change the visible From.

DMARC on the sender's domain looks at Header From alignment. A hop that rewrites From to itself can break or 'fix' mail in ways you will not like when a bank checks the original.

You are not buying inbox placement. Destination Gmail still files, filters, and delays. Anyone selling a percentage is selling a different story.

You are not buying leftover MX cleanup as a managed service unless the runbook says so. Most vendors will tell you to delete the old rows. MailerZ treats leftovers as a hard stop.

Checklist groups: MX, From, logs, HOLD, limits
Score groups, not vibes.

The 25-point checklist

Use this list in order. A fail on points 3, 5, 17, or 23 is usually enough to walk. Score the rest.

  1. Public NS name the panel you will edit. A pretty zone on the wrong account is fiction.
  2. The vendor prints MX hostnames. You copy them. You do not invent mx1.example from memory.
  3. After cut, two public resolvers show only that MX set. Two brands is leftover MX.
  4. The vendor treats leftover MX as a hard stop, not as 'eventual consistency.'
  5. Header From is not rewritten. Envelope rewrite (SRS) is a different, honest job.
  6. Subject, Date, Message-ID, body, and MIME stay intact. A 'helpfully flattened' MIME is a new product.
  7. You can name the catch-all policy: HOLD, FORWARD, or reject. Default mystery is a no.
  8. Unknown FORWARD does not land in a shared vendor dump you cannot export.
  9. Named aliases exist. You are not forced into plus-addressing as the only isolation.
  10. You can disable one leaked alias without renaming the domain.
  11. Hop history or SMTP transcripts exist for mail the vendor accepted.
  12. Empty history is documented as 'never arrived,' not as a spam shrug.
  13. Store window is printed. Fourteen days versus ninety days is a buying difference.
  14. The store is not sold as an archive or legal hold.
  15. Send-as exists only if you need it. The free tier must say if it does not.
  16. SMTP values come from a dashboard. Ports and hosts are not tribal knowledge.
  17. Unauthorized send gets 550 5.7.1 or equivalent. Open relay is an immediate fail.
  18. Self-send caveats are documented. The vendor tells you to probe from another mailbox.
  19. Plan limits for domains, aliases, seats, and outgoing are on a pricing page you can cite.
  20. Seat means a login, not a mailbox tax pretending to be forwarding.
  21. You can export the alias map. Lock-in by screenshot is a fail.
  22. Support can see a hop without asking you to paste secrets in a public ticket.
  23. The vendor does not claim SOC 2, ISO, HIPAA, or inboxing percentages it does not have.
  24. You can cancel and leave exclusive MX on a successor the same day. No hostage DNS.
  25. A live probe during the trial matched these points. Paper alone is not a choose-an-email-forwarding-provider decision.

Print the list. Check boxes with dates. A checklist you keep in your head will shed the leftover-MX row the first time a registrar UI gets ugly.

Failure modes and proof

Vendor marketing says 'works with Gmail' and your self-send test is green while customer mail hits leftover Microsoft MX. Proof: two resolvers, not a selfie.

Vendor rewrites From and your DMARC reports look 'better' because they now align to the hop. That is not better. That is a different sender.

Vendor has no hop log. You will debug with destination spam folders and folklore.

Vendor catch-all FORWARDs to you and a leaked random string becomes a password-reset oracle.

Vendor SMTP is an open secret shared in a blog. Rotate. Prefer dashboard-issued credentials.

Proof artifacts: resolver listings, probe message IDs, a raw header showing From, an SMTP 550 for a forbidden send, and a pricing URL dated the day you bought.

MailerZ workflow and product boundary

MailerZ scores itself on this list as a focused custom-domain forwarder plus authenticated SMTP. Envelope SRS only. Header From never rewritten. Not Workspace. Not IMAP. Not an open relay.

Free: one domain, three aliases, one seat, fourteen-day store, fifty outgoing a month, HOLD unknown, no send-as.

Paid plans add domains, aliases, ninety-day store, optional FORWARD, and send-as with hourly caps. Solo is forty dollars a year. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Confirm /pricing.

Leftover MX is a hard stop. Self-send can fail. Probe from another mailbox. Unhosted recipients get 550.

No SOC 2, ISO 27001, HIPAA, uptime SLA, or inboxing number. /security is the control story, not a badge wall.

If MailerZ fails a point you marked as mandatory, do not invent a workaround in a spreadsheet. Pick another class of product.

Cost and alternatives

Forwarding is cheap compared with per-user suites. It is expensive compared with 'leave the registrar MX' only until the first lost customer.

Cloudflare Routing can win a price score and lose on logs and send-as. Put that in the grid honestly.

ImprovMX and ForwardMX sit in-class. Run the same twenty-five points the same week. Do not reuse a year-old table.

Mailbox hosts win IMAP and lose the 'keep Gmail' story. Suites win collaboration and lose the cheap-alias story.

Hide My Email and consumer masks win anonymity-ish and lose company identity. They are a different checklist.

Pay for the plan that matches send-as and store. A founder on Free who promised From domain@ to a bank chose the wrong row.

How to score a live trial

Use a lab domain or a spare. Do not trial on the live invoice domain with dual MX 'just to see.'

Day zero: NS, MX exclusive, leftovers gone, two resolvers agree.

Day zero plus one hour: unique probes to two aliases. Save hop lines. Open original headers.

Day one: attempt send-as on the free tier. If it 550s, that is a data point, not a surprise.

Day two: send to a typo. Confirm HOLD or reject matches the docs.

Day two: disable one alias. Confirm it 550s or holds. Confirm the other alias still lives.

Write the score in the ticket. Then choose. Choosing during the demo call is how leftover MX survives.

When to walk away

Walk if the vendor rewrites Header From and you talk to banks, payroll, or any DMARC-strict receiver.

Walk if they cannot show a hop and tell you to 'check spam.'

Walk if leftover MX is shrugged off as propagation after both resolvers show two brands.

Walk if they claim a badge they will not show, or an inboxing percentage.

Walk if SMTP works without credentials. That is not convenience. That is a relay.

Walk if you needed IMAP. You used the wrong checklist. That is on you, not on the vendor.

Stay only if the live trial matched the points you marked as mandatory. Choose an email forwarding provider once. Migrating twice is how agencies get famous for the wrong reason.

Live trial: two resolvers, third mailbox, 550 on unauthorized send
Paper plus a probe. Not paper alone.

Helpful-content bar: Google Search documentation. Use it on this page too.

Worked scenarios for the 25-point score

Vendor A is free and rewrites From. Your DMARC reports look tidy. A bank still rejects the hop. Point 5 fails. You walk. Choose an email forwarding provider that fails loudly on From, not politely on a dashboard.

Vendor B has beautiful logs and leftover MX in both resolvers after you asked them to cut. They say wait forty-eight hours. Both views show two brands. Point 3 fails. You delete the other name yourself or you leave.

Vendor C has no send-as and you told a customer you would reply From the domain. Point 15 was a skip you should not have skipped. That is a scoring error, not a vendor ambush.

Vendor D 550s an unauthorized send. Point 17 passes. You are happy. That 550 is the product working.

Vendor E lets you export the alias map as JSON. Point 21 passes. Vendor F makes you screenshot. You will mis-type a destination on the way out.

You trial two vendors on two lab domains the same week. You do not dual-publish them on the live invoice domain. The checklist assumes a clean exclusive set. Dual trial on production is leftover MX dressed as science.

An agency applies the list per client. Client 3 needs IMAP. The checklist tells you to walk to a host for that client only. One roster, two classes. That is allowed.

Practice and anti-patterns while scoring

Practice: print the twenty-five points. Anti-pattern: a vibe after a sales call.

Practice: date the pricing URL. Anti-pattern: a number from memory.

Practice: third mailbox. Anti-pattern: self-send as the only score.

Practice: two resolvers. Anti-pattern: one 'what's my DNS' widget.

Practice: a 550 on purpose. Anti-pattern: assuming authorization exists.

Practice: disable one alias. Anti-pattern: assuming disable exists because create exists.

Practice: walk on a hard fail. Anti-pattern: 'we can mitigate with dual MX.' Dual MX is a new fail.

Choose an email forwarding provider the way you choose a lock: after you turn it, not after you like the brass.

Operator closeout after the trial

Write the score table with dates. Keep the probe IDs. Keep the resolver listings. Keep the 550. Keep the pricing URL.

Name the hard fails. If there were none, say so. If there were mitigations, they are probably leftover MX. Strike them.

Pick one vendor. Schedule the exclusive cut. Do not keep the loser published 'as backup.' Backup is the drain store, not a second MX.

If you picked MailerZ, closeout includes the plan you actually need: Free inbound versus Solo send-as versus a fleet plan. Confirm pricing the same day.

If you picked someone else, this page still did its job. The checklist is not a funnel trick.

Tell the people who print addresses which hop won and when leftovers die.

Set a quarterly re-score if the vendor can change From handling or logs. Providers drift. Your twenty-five points should not.

Edge cases the checklist still catches

A vendor that is also a campaign sender. If they will blast from your domain without a separate authorization story, point 17 is in danger. Walk or isolate.

A vendor in a region you cannot reach. Empty hops that are really path MTU or blocking will look like leftover MX. Prove with a second network before you delete a name that is already exclusive.

A vendor that stores mail in a country you cannot accept. The checklist did not have a residency row. Add one if counsel needs it. MailerZ will not invent a residency SLA here.

A vendor acquired by a suite company. Re-score From handling the week the press release lands. Acquisitions rewrite products.

A vendor whose free tier is HOLD and whose paid tier silent-FORWARDS. Read the plan you will live on, not the trial.

A vendor with a status page and no hop IDs. Status is not point 11.

You. If you needed IMAP, the checklist cannot save you. Buy a host. Do not punish a forwarder for a class error.

Field notes from scores that changed a buy

The checklist only works if you let a hard fail kill the vendor. Teams that 'mitigate' leftover MX with patience will pick the pretty logo every time. Choose an email forwarding provider after you have walked away from one. Walking is a skill.

From rewrite is the fail people excuse because DMARC reports get quieter. Quieter is not aligned with the original sender. Banks care about the original. If you talk to banks, point 5 is not optional.

Logs are the fail people excuse because they 'can always look in Gmail.' Gmail cannot tell you the probe never arrived. Empty hop versus spam folder is the whole job of a forwarder log.

Pricing pages move. Date the URL. A lifetime deal that hides send-as is how you promise a From you cannot send.

Agencies who score once and reuse the table for a year will ship a dead vendor. Re-score after acquisitions and after a From-handling changelog.

If you needed IMAP, you will hate every honest forwarder. That hate is information. Buy a host.

MailerZ will fail points you marked if you needed a badge or an inboxing number. That is the list working. Do not invent a workaround in a spreadsheet.

Two lab domains, one week, same points. Anything else is folklore.

Handoff memo for the next buyer

Attach the dated score table, probe IDs, resolver listings, 550 output, and pricing URLs. The next buyer should not re-do folklore. They should re-run only what drifted.

Name the hard fails you accepted, if any. If you accepted leftover MX, you did not finish the checklist. Say that so they can fix it.

Name the class: forwarder, host, suite, or mask. Mixed classes in one table are how people buy Workspace to solve From rewrite.

If MailerZ won, write which plan and why. Free inbound versus Solo send-as is a different score.

Set the re-score date. Providers drift. Checklists that never run again are décor.

Acceptance criteria for the choice itself

Every mandatory point has a dated artifact, not a memory.

The winner is exclusive on the target zone. The loser is not published as backup MX.

Self-send was not the deciding artifact.

The people who print addresses know which hop won and when leftovers die.

If you chose MailerZ, start-free on a lab happened before the live cut. If you chose someone else, this page still applies the next time.

Operations review of a living choice

A choose-an-email-forwarding-provider decision is not finished at purchase. Once a month, pick three points at random and re-prove them. From handling, leftover MX, and logs are the first three if you are tired.

Watch the vendor changelog. Acquisitions, From-rewrite 'improvements,' and free-tier silent FORWARD are how last quarter's winner becomes this quarter's fail.

Keep the lab domain. Re-running twenty-five points on production with dual MX is how science becomes leftover MX.

If support can no longer find a hop ID, point 11 failed in production. Open a ticket and start a re-score. Do not wait for a lost invoice.

If you promised send-as to a customer, re-check the plan cap before a campaign week. Caps are not SLAs, but they are still walls.

If you are an agency, re-score per class of client, not once for the whole roster.

If MailerZ is the winner, confirm leftover MX language is still in your runbook. Products can stay honest while operators drift.

Quarterly re-score

Print the twenty-five points again. Date a new pricing URL. Run two resolvers. Run two probes. Run one unauthorized send. Run one disable.

Compare artifacts to last quarter. Drift in From handling is a walk, not a meeting.

If you added IMAP needs, you left the class. Stop scoring forwarders for a host job.

If security review now requires a badge MailerZ does not have, write no and change class or change the requirement.

Update the handoff memo with the new artifacts.

Tell the people who print addresses if the hop changed. They will not read the ticket.

If nothing drifted, write 'no drift' and keep the date. Empty reviews still count.

Appendix notes

Appendix: a vendor that is also a campaign sender can fail point 17 quietly. Isolate campaigns. Choose an email forwarding provider for the hop, not for a blast.

Appendix: path MTU and national blocks can look like leftover MX. Prove from a second network before you delete an exclusive name.

Appendix: add a residency row if counsel needs one. This checklist did not invent a MailerZ residency SLA.

Closing notes

Closing note: walk on a hard fail once so the next score is cheaper. Choose an email forwarding provider after you have deleted a pretty logo. That memory is worth more than a comparison table.

FAQ

What is the safest way to choose an email forwarding provider?

Score exclusive MX, From rewrite policy, leftover MX, logs, catch-all, send-as, store, and support with a live probe. Do not pick from a logo row.

Does this require a new mailbox?

No. Forwarding exists so you can keep Gmail or Outlook. If the vendor requires IMAP, you left the forwarding class.

Will it work with Gmail or Outlook?

It should, as destinations. Self-send is not the score. Use a third mailbox. Confirm send-as separately.

What DNS records are involved?

Exclusive MX, verification TXT, leftovers deleted. SPF and DKIM if you send. NS must match the panel. See RFC 5321 and RFC 7208.

What should you test before production?

Unique probes to each public alias, hop lines, Header From intact, leftover MX absent at two resolvers, and a 550 on an unauthorized send.

When should you not choose a forwarder?

When you need IMAP folders, a legal archive, or a badge the vendor does not have. Buy a host or a suite for those jobs.

Key takeaways

  • Choose an email forwarding provider with twenty-five written points, not a vibe.
  • From rewrite is a disqualifier for DMARC-sensitive mail.
  • Leftover MX must be a hard stop in the runbook.
  • Logs beat marketing. Empty hop is not 'in spam.'
  • Free tiers hide send-as and store limits. Read them.
  • MailerZ: SRS envelope, intact Header From, not IMAP.
  • Confirm /pricing. Do not quote memory.
  • Walk away when you need a suite or a badge they lack.

Conclusion and next action

Choose an email forwarding provider by scoring exclusive MX, intact Header From, leftover-MX handling, hop history, and honest limits. MailerZ publishes those constraints. It does not publish an inboxing SLA or a compliance badge. Start free, run the twenty-five points, and only then print the domain on invoices.

Ready to score the hop

Start free on one domain and run this checklist against a live probe.

Inbound on Free. Paid when send-as and store window matter. Sign in if you already started.

Review quarterly, or sooner if provider behavior, pricing, or MailerZ scope changes. Author: MailerZ editorial, Secuno LLC.