Earlier quoted context omitted.
Be careful: By hosting your main email on a custom domain(not a provider) you open a new attack vector for identity theft. Someone can hijack your godaddy/namecheap/gandi account and point the MX DNS records of the domain to their own server and receive all your "Forgot your password? here is the link to reset!" emails This a very bad advice unless you actually know what are the risks.
Is there a good way to protect against this aside from good password hygiene at your domain registrar? I use namecheap if that is relevant--maybe there's a better/more secure registrar to move to. But I guess, equivalently, someone can just equivalently hijack your email account directly if you use a service like Gmail or Yahoo.
The thing is, of course people can hack your gmail or yahoo mail somehow, but when you host your own domain, you have the same attack vectors + dns hijacking and this last addition is easier to exploit with social engineering. Google atleast is virtually immune to DNS hijacking.