Email is increasingly difficult to do yourself with the proliferation of anti-spam and anti-malware protection, combined with consolidated usage of SaaS apps for email across the board. Most of the IP address space in AWS and Azure is blacklisted by spam filters (as is customer IP space from most ISPs if they don’t already filter SMTP traffic), so unless you want to roll the dice on config settings for everyone you send email to, you’re generally going to need an authenticated relay for outgoing mail — and your best option will be one of the big cloud providers.
If you want a secure mail service that won’t read your email, try ProtonMail.