The call usually starts the same way. A client sends an invoice, the customer says it never arrived, and the message turns out to have been sitting in a junk folder for three days. The mailbox came free with the web hosting plan, set up years ago by whoever built the site, and nobody has looked at it since.
That is the real decision most small businesses face. Not Google Workspace against Microsoft 365, which people choose deliberately, but Google Workspace against the mailboxes bundled with hosting that cost nothing extra. Free is a strong argument. Here is what we check before telling a client to switch, and when we tell them not to bother.
What each option actually gives you
Hosting email means your mailboxes live on the same server as your website, managed through cPanel or your provider's own panel. You get a mailbox per address, webmail, IMAP and POP access, and a shared outbound mail server. Storage comes out of the hosting disk quota, and administration is a form in a control panel.
Google Workspace is a separate mail platform. Your MX records point at Google instead of your host, mail never touches the web server, and each person gets a Gmail mailbox plus Drive, Calendar, Meet and Docs. Administration happens in the Admin console: users, groups, aliases, security policy, audit logs.
The feature lists are easy to compare and mostly beside the point. Four things decide it: whether your mail arrives, what happens to the data when someone leaves, what a takeover would cost, and the twelve-month bill. In that order.
Shared reputation: the problem you do not see until mail bounces
This is the one that brings people to us, and it is structural rather than a misconfiguration you can tidy up.
On shared hosting, the outbound mail server is shared with every other site on that machine, and receiving providers judge the sending IP. If another account there buys a list or gets compromised and starts sending, the IP's reputation drops and your invoices go to spam alongside their spam. You did nothing and you have no lever to pull.
Hosting providers know this, which is why they publish sending caps. Hostinger, to take one whose limits are public, documents caps per day, per hour and per message on cPanel email, and separately warns that mail sent through PHP's mail() function is capped at 100 messages a day and 10 a minute, recommending authenticated SMTP instead (checked 30 September 2026). Those caps protect the shared IP. They are also the ceiling on your order confirmations.
The second half of the problem is authentication. Gmail's sender guidelines require every sender to publish SPF or DKIM for the sending domain, to have valid forward and reverse DNS on the sending IP, and to use TLS. For mail sent to personal Gmail addresses, the domain in the From: header has to align with either the SPF domain or the DKIM domain. Bulk senders also have to keep the spam rate in Postmaster Tools below 0.30%, and marketing messages need one-click unsubscribe.
None of that is impossible on hosting email: DKIM signing is often in the panel, and SPF is a TXT record you can write yourself. But you are authenticating a sender whose reputation you share with strangers, and a growing business eventually hits a cap it cannot raise. With Workspace, SPF is one include and Google signs with DKIM once you enable it:
; SPF, if Google Workspace is your only sender
example.com. TXT "v=spf1 include:_spf.google.com ~all"
; MX, one record
example.com. MX 1 smtp.google.com.
Read Google's SPF documentation before editing anything: a record holds at most ten include: lookups, and hosting records tend to be crowded already.
Either way, check what your domain publishes today. A missing SPF record, unsigned DKIM or a stale hosting include is worth fixing on whichever platform you choose.
Storage, backup, and the day somebody leaves
Hosting mailboxes eat the hosting plan's disk. That works until it does not: a sales mailbox with ten years of attachments fills the quota, the site starts throwing errors, and the fix is to delete old mail or buy a bigger plan. Backups are whatever your host takes of the whole account, on their schedule.
Workspace storage is pooled across the organization rather than fixed per mailbox. Business Starter includes 30 GB per user, Business Standard 2 TB, and Business Plus and Enterprise Plus 5 TB, all drawn from one shared total. Pooled is the useful part: one person with a huge mailbox does not break anyone else.
Offboarding is where the gap gets uncomfortable. On hosting email, deleting a mailbox deletes the mail, and there is no built-in handover. In Workspace, deleting a user is a guided process: a super admin can transfer the departing person's Drive and Docs files and primary Calendar data to another account, and the account stays suspended until the transfer finishes. Google also documents that the deleted address is removed from the organization twenty days later, which is your window to restore an account you deleted in haste.
Where one person owns the client relationships, this is not an administrative detail. It is whether you keep the history when they resign.
Security: two-step verification, devices, recovery
Hosting mailboxes are usually protected by a password in a panel. Some providers offer a second factor on the hosting account itself, far fewer per mailbox, and almost none give you a way to require it. If a salesperson reuses a password that later turns up in a breach, you find out when customers receive invoices carrying someone else's bank details.
In Workspace, two-step verification is a policy you enforce rather than a setting you hope people find. The Admin console lets you turn it on for the whole organization or for a single organizational unit, and you can require security keys or passkeys specifically. Google's own guidance is to enforce security keys across all organizational units, with the caveat that in security-key-only mode users cannot generate their own backup codes, so an admin has to hand them out. That last detail matters: enforcement without a lockout plan creates a different emergency.
You also get what only exists on a managed platform: audit logs of who signed in from where, the ability to sign a stolen device out, and password resets that do not need a support ticket.
The real twelve-month cost
Hosting email looks free because it is bundled. It is not free, it is unpriced: you pay for it inside the hosting plan, and the disk quota is the budget.
Workspace is a per-user subscription, and the number that matters is the twelve-month total for the licenses you genuinely need, not the monthly headline. Two things move it. First, the payment plan: Google's billing documentation is explicit that the Annual/Fixed-Term plan carries the lowest per-user monthly price but commits you to a minimum license count you cannot reduce until renewal, while the Flexible plan bills monthly for the users you have, prorated, and lets you remove accounts at any time. With seasonal staff, Flexible usually wins even at the higher unit price. Second, the license count, which is where most quotes go wrong.
We read the current figure off Google's pricing page when we quote, rather than repeating one from memory, because list prices and introductory offers change. What we can tell you is how to count licenses:
- Aliases are free. Google documents up to 30 email aliases per user at no extra cost, so a person who needs
sales@andana@needs one license and one alias, not two licenses. - Shared addresses are groups, not users. An alias belongs to one person, so
info@,support@andfacturacion@should be Google Groups that deliver to several people at no license cost. - Not everyone needs the same edition. If two people need the larger storage and meeting recording and the rest only need mail, the whole company does not have to sit on one plan.
- Count what sits outside the subscription. Migration, a day of training and DNS work are real and one-off. Quote them separately.
Our own rates sit on how we work. A company of twelve people often needs eight licenses, and an honest count changes this comparison more than the plan choice does.
When hosting email is genuinely enough
We talk clients out of migrating more often than you would expect. Hosting email holds up when all of these are true:
- Two or three mailboxes, low volume, mostly replies rather than outbound campaigns.
- Nothing automated sends on the domain's behalf: no e-commerce order confirmations, no CRM, no invoicing system, no newsletter.
- The mailboxes are not the record of anything anyone would need to read later.
- Your provider gives you DKIM in the panel and you have published SPF and DMARC properly.
- Nobody depends on shared calendars or shared files, which is the half of Workspace this comparison ignores.
A two-person studio invoicing by hand is fine. A ten-person firm whose accounting software emails clients is not. That is usually the line.
How we migrate when a client decides to switch
The order matters more than the tooling. Doing it out of order is what produces the lost-mail stories.
- Inventory first. Every mailbox, forwarder, alias and autoresponder, plus everything that sends using the domain: the contact form, the invoicing system, the CRM, the printer.
- Create users as you will pay for them. People as licensed users, shared addresses as groups, secondary ones as aliases.
- Copy the mail with the old system still live. Migration runs over IMAP while hosting mail keeps delivering, so nothing is in flight at cutover.
- Lower the MX TTL two days ahead, not on the morning of the cutover.
- Change the MX records, then authenticate the same day. SPF updated for the new sender, DKIM enabled and published, DMARC at
p=nonewith reports going somewhere you read. - Re-point everything still sending through the old server. This is the skipped step, and it is why order confirmations fail a week after an otherwise clean migration.
- Watch the DMARC reports for two weeks before tightening the policy.
The full runbook, including the IMAP copy and the cutover hour, is in our guide to moving email off cPanel hosting.
How Guanacos Tech helps
We run this comparison as an audit or as the first step of a migration, and it takes about an hour: what your domain publishes, where mail actually leaves from, how many licenses you would really need, and whether the mailboxes hold anything you cannot afford to lose. Sometimes the answer is that your hosting email is fine and the SPF record is the thing to fix. We say so.
Our Google Workspace consultants will walk your domain with you on a 30-minute call and tell you what we would change, in what order, before anyone touches DNS.
Sources
- Google Workspace Help: Compare Business editions
- Google Workspace Help: Compare Flexible and Annual/Fixed-Term payment plans
- Gmail Help: Email sender guidelines
- Google Workspace Help: Set up SPF
- Google Workspace Help: Set up MX records for Google Workspace
- Google Workspace Help: Delete or remove a user from your organization
- Google Workspace Help: Deploy 2-Step Verification
- Hostinger Help: Parameters and limits of cPanel Email
- Hostinger Help: PHP Mail limitation explained
- Google Workspace Help: Add additional email addresses for users