Microsoft 365 Email Migration Perth — Moving from cPanel Without Losing Your Mind
Five years of email through your hosting account. It works, mostly. Then three things go wrong in the same week: a client mentions your invoices are landing in their spam folder, your accountant asks for an email archive trail for an ATO audit, and one of your staff can't figure out how to enable MFA because cPanel email doesn't really do that.
If you've already decided Microsoft 365 is the answer, this post is the how-to. If you're still on the fence, head over to our post on why cPanel email is a bad long-term choice for business — we won't rehash the case here.
What follows is the migration process in plain English: the right order of operations, what can go wrong, and how to make sure you don't lose a single email.
The Right Order of Operations
Here's how we run Microsoft 365 email migrations for Perth businesses, and the order matters.
Step 1: Set up Microsoft 365 and configure Exchange Online
Step 2: Flip the MX records so new mail routes to Microsoft 365
Step 3: Pull the historical email across from cPanel
You're probably thinking: won't I lose email between steps 2 and 3? No — because once the MX records point to Exchange Online, new mail is landing there. The historical data you migrate afterwards fills in the archive. You're not racing against live mail flow; you're backfilling history at your own pace after the live system is already working.
The method we don't use: migrating all the historical data first, then flipping MX records. It sounds sensible but it means your staff are sitting in cPanel during the migration window, then scrambling through a cutover. Our approach gets people onto Microsoft 365 — with working email — faster.
Before You Touch Anything: The Audit
Before creating a single account in Microsoft 365, you need a complete picture of what's in cPanel.
Count Every Mailbox, Alias, and Forwarder
Log into cPanel and list everything: active mailboxes, email aliases (addresses that forward to a real mailbox), forwarders (addresses that push mail to an external address), and any autoresponders. Every single one needs a plan before migration day.
Aliases become additional email addresses on an Exchange mailbox. Forwarders that push to an external Gmail or personal account need a conversation with whoever owns that workflow. Autoresponders get recreated manually in Exchange Online. None of this is hard — but finding out you missed three aliases after you've already cut over is annoying.
Check Your Domain's DNS Records
You need admin access to your domain's DNS before migration day, not during it. Confirm you can log in to wherever your domain DNS is managed and that you know which records you'll be changing. The MX record is the main one. You'll also be adding or updating SPF, DKIM and DMARC records — these are critical for email deliverability and something a lot of migrations skip. Don't skip them. We've got a full post on email authentication setup for Perth businesses if you want the detail.
Decide on Licensing Before You Start
Microsoft 365 comes in several tiers and the right one depends on your business. For most Perth small businesses, Business Basic covers email. Business Standard adds the desktop Office apps. Business Premium adds Defender and Intune — worth it if you want proper endpoint security. If you're comparing Premium vs Standard, this post breaks it down.
Get licensing sorted before you start provisioning accounts. Adding licences mid-migration creates confusion about who's live and who isn't.
Step 1: Set Up Microsoft 365
Create the tenant, add your domain, create user accounts, assign licences, and configure Exchange Online. This includes:
- Creating mailboxes for every active user
- Setting up any shared mailboxes (reception@, accounts@, info@)
- Recreating distribution lists
- Adding email aliases to the right accounts
- Configuring MFA for every user before they touch the new system
On that last point — MFA setup before go-live, not as an afterthought. Microsoft 365 without MFA is a significant security exposure. If you want to understand what proper Microsoft 365 security looks like beyond just MFA, this post covers it.
At this stage, your cPanel email is still running normally. Nothing has changed for your users. You're just building the destination.
Step 2: Flip the MX Records
Once Microsoft 365 is configured and tested, you update your MX records to point to Exchange Online.
DNS changes propagate across the internet over minutes to hours depending on your TTL settings. During propagation, some mail may still hit cPanel briefly — that's fine, it'll sit there and you can grab it. Once propagation is complete, all new inbound mail goes straight to Exchange Online.
At this point, your users switch to Outlook (desktop, web, or mobile). They're on Microsoft 365. Email is live.
Update your SPF record at the same time to authorise Microsoft 365 as a legitimate sender for your domain. Add DKIM records from the Microsoft 365 admin panel. Set up DMARC. Do all three — not just SPF. Skipping DKIM and DMARC is one of the main reasons business email ends up in spam folders even after migrating to a proper platform.
Step 3: Migrate the Historical Email
Now that your users are live on Microsoft 365, you go back and pull the historical mail from cPanel into Exchange Online.
We do this using IMAP migration — Microsoft 365 connects to your cPanel mail server and pulls everything across folder by folder. For most small business mailboxes, this takes anywhere from an hour to a day depending on mailbox size. Users can keep working throughout; the historical mail simply appears in their inbox as it comes across.
A few things to know:
- Folder structure comes across intact in most cases
- Very old mail (pre-2015 on some cPanel setups) can be hit and miss — worth checking
- Shared mailboxes and aliases need separate migration runs
- Once you're happy the migration is complete, you can leave cPanel email active for a few weeks as a safety net before removing it
What Actually Goes Wrong
Migrations don't usually fail dramatically. They fail in small, annoying ways that cost time.
SPF/DKIM/DMARC not updated properly. Mail starts landing in spam. The fix is straightforward but fixing it after the fact means re-educating clients who've already flagged you as junk.
A mailbox was missed in the audit. The forwarder for orders@ that nobody remembered is now bouncing because the destination account doesn't exist in Microsoft 365 yet.
A user's phone isn't reconfigured. They're getting mail on their laptop but their phone is still pointing at the old cPanel IMAP settings, so replies from the phone are going out from the wrong account or not at all.
MFA breaks a legacy application. Some older line-of-business apps use basic SMTP authentication, which Microsoft 365 disables by default for security. If you have software that sends email (accounting software, a CRM, a booking system), test this before go-live.
None of these are showstoppers. They're just easier to handle if you know to look for them.
After Migration: Don't Leave Loose Ends
Once you're live on Microsoft 365, a few things to sort within the first week:
- Confirm SPF, DKIM and DMARC are all passing (use MXToolbox or similar)
- Check that no users are still sending from the old cPanel account
- Update any website contact forms that use cPanel SMTP to send
- Update email signatures across the business
- Make sure your backup covers Exchange Online data — cloud data still needs a backup strategy
On that last point: Microsoft 365 is not a backup. It has some retention features, but they're not the same as a proper backup with point-in-time recovery. Worth factoring into your setup.
How We Handle This for Perth Businesses
We manage Microsoft 365 email migrations for Perth small businesses regularly. We're here during business hours — same time zone as you, same working day — so when something needs attention during a cutover, you're not waiting on an overseas support queue to catch up.
If you've been putting off moving off cPanel email because it sounds like a headache, it's genuinely not — when it's done in the right order. Get in touch and we can walk you through what the migration would look like for your setup.

