This is pretty well trodden ground, between people here and google of decades of history you'll have no problem. Don't forget to implement the arrows flipped around, I sent all my outgoing thru my cloud server after authentication, so everything goes in and out the same way. Eventually I gave up because in my situation forward everything to gmail is not an issue for me; email is just a spam and amazon receipt delivery service, so its not worth much effort.
Anyway one interesting design aspect is you're going to fetchmail from home to a cloud pop server and you'll want to secure that, so the natural inclination is to take smallest possible steps while testing all the way, first you try an unusual port number to keep scanners away, maybe you only allow the big netblocks from your provider (not specific /32 addrs but if your provider gives you an addrs from a /19 well then permit the whole /19) then all manner of SSL/TLS protocols instead of plain text passwords and things like that.
But I'd advise saving a lot of time and going big for security before even playing with the mail system. So put openVPN on the cloud provider and have your home and your phones/tablets/laptops/friends/family can VPN into your big happy psuedo-internal LAN... don't let "the internet" connect to your cloud pop (imap?) server at all, only allow connections from internal (via VPN) addresses. You're probably going to end up doing it sooner or later and a VPN'd config obsoletes quite a bit of internet accessible stuff for the pop server. You can have a perfectly static internal LAN addrs for homebox and cloudbox over the VPN, even if endpoint addrs change, which makes some simple ip address firewall rules easier than if both endpoints were dynamic. So by the magic of openvpn 10.1.0.0/16 is in the cloudbox and 10.2.0.0/16 is at home, all the time forever, regardless of current provider both at home or cloud, which makes it pretty easy to create static iptables rules and such.
I find it handy to have my phone and tablet always on my home network, because I have fun stuff on my home network. So I'm going to be doing this anyway... may as well use the same security infrastructure to secure my fetchmail sessions rather than trying to secure them on the open internet.