* Encryption in transmission emails sent and received, using SSL/TLS
* Encryption in transmission of webmail sessions, using HTTPS
* Authentication security: Do they use 2 factor or other tech?
* Logging and retention of logs
* Reading your mail to build marketing profiles and social graphs
* Access by employees to your data
* Retaining and sharing your personal data with other businesses
* Security of your account information; can they easily be persuaded to surrender it
* Security of the email provider's systems
* Responsiveness to 3rd party requests for your information, whether private parties in lawsuits or legal authorities with/without warrants
* Cooperation with government surveillance dragnets
Security always is a matter of degree. Email will never be perfectly secure but there are some big differences between providers.