Email services for agents
The target namespace is currently clean: it resolves but carries no MX records at all, so agent mail can be stood up there without touching the Microsoft 365 tenant already serving the main domain. A misconfigured agent sender then cannot affect staff mail.
The decision that comes first is not which vendor, but whether an agent needs a mailbox or only a sender. An agent that emails out and never reads replies needs an API sender: cheap and simple. An agent that holds a conversation needs a real mailbox with IMAP, which is a different product at a different price. Most agent workflows need the first and get sold the second.
On redundancy: the mail node should sit outside the same failure domain as the edge and CDN. If both are with one provider, a single outage takes the site and the ability to tell anyone about it.