We can do a risk profile for an email with a custom domain versus a gmail domain.
Do we need to differentiate between custom email domain with self-hosted mail server and custom email domain with gmail?
If I self-host the mail server then I’ll have a machine running on digital ocean or ec2 and this machine will accept connections from the Internet. I think this machine should be included in the assessment. So now the risk of a custom email domain depends on when/how I apply patches and how ssh access is configured?