Organizations still self-host email in 2026 for three reasons: data residency requirements, cost at scale beyond a few hundred mailboxes, and avoiding foreign cloud dependency for a system core to daily operations. Cloud email remains the default for good reason — someone else runs the servers, patches CVEs, and answers pages at 3 a.m. — but that convenience has a real, calculable price for organizations above that threshold.
The math changes at scale
Per-seat SaaS pricing is easy to justify at 50 mailboxes and hard to justify at 10,000. We migrated one 10,000-mailbox institution off a commercial suite and the estimated operating cost dropped from roughly 3 billion Tomans a year to under 200 million — because the marginal cost of the 10,001st mailbox on your own infrastructure is close to zero, and it never is on a per-seat plan.
Dollar-billed SaaS on a currency that isn't the dollar
For organizations under sanctions exposure, a subscription priced and billed in USD carries currency risk the finance department has no control over, on top of sanctions exposure that can turn into an access problem with no warning. Self-hosted email removes both: there's nothing to bill in a foreign currency and nothing a foreign platform can suspend.
What actually has to be right
Self-hosting email badly is worse than not doing it — deliverability, spam filtering, and TLS certificate hygiene are unforgiving. The parts that matter: a modern protocol (JMAP, not 1990s IMAP, for anything resembling a decent webmail experience), SMS one-time-password login since email-based password reset is circular on your own mail server, and monitoring that actually pages someone when the queue backs up rather than a mailbox silently not delivering for six hours.
None of this makes cloud email the wrong default. It makes self-hosting the right non-default for a specific profile: large enough that per-seat pricing hurts, and constrained enough — by currency, regulation, or data residency — that "someone else's server" isn't actually simpler.