Business email looks simple from the inbox. Behind it sits identity, historical data, routing and sender trust. We moved each part deliberately so conversations with Lejiend could continue through the change.
Lejiend has completed its email-provider migration from Zoho Mail to Microsoft 365. Historical messages now sit in Exchange Online, new mail is routed to Microsoft's provider-managed mail servers and Outlook has become the working home for our business communication.
We are sharing the process because infrastructure work becomes more useful when the decisions are visible. This account omits mailbox identities, credential mappings and provider-specific account tokens, while preserving the practical sequence another small team can learn from.
The migration in four phases
Secure temporary access
We generated an application-specific Zoho password for authenticated IMAP access and mapped each source account to its Microsoft 365 destination. The temporary credential was used only for migration and revoked after completion.
Move the mailbox history
We created a secure IMAP migration endpoint in Exchange Online, uploaded the protected mapping and synchronized hundreds of messages across 11 folders before completing the migration batch.
Redirect live mail
In Cloudflare DNS, we removed the previous Zoho mail routing and directed new delivery to Microsoft 365. We also updated sender authentication and configured Autodiscover as DNS-only.
Prove the new route
We confirmed a healthy domain status, tested delivery from an external mailbox, allowed synchronization to settle and finalized the Exchange Online migration batch.
What changed in DNS
DNS is the public instruction layer for email. The MX cutover changed the provider mail servers responsible for receiving new Lejiend messages, while the authentication records help receiving systems evaluate legitimate senders.
The MX record tells other mail systems that Microsoft 365 is now responsible for receiving Lejiend email.
The SPF record identifies Microsoft 365 as an approved sender for the domain and helps receiving systems detect unauthorized sources.
The CNAME helps supported Outlook clients locate the correct Exchange Online configuration automatically.
One mailbox, several business purposes
Role-based addresses continue to give customers clear destinations for different conversations, but they route into one managed Microsoft 365 mailbox. That keeps the public experience organized without creating unnecessary standalone mailboxes.
Those aliases are not published in this technical recap. Describing an architecture does not require publishing the underlying account identity or migration mapping.
Hardening continues after migration
Completing mail flow is the operational milestone, not the end of email security. Our follow-up work includes reviewing DKIM and DMARC, monitoring delivery health and periodically testing each role-based address from outside the organization. These are continuing hardening actions, not claims that every control is already active.
Official references
We used provider guidance to confirm the purpose and expected configuration of the migration and DNS controls.
The visible result is a familiar inbox. The meaningful result is that Lejiend now has a completed, documented email foundation on Microsoft 365—and a migration record we can use when the system evolves again.
