123.123.123.123.sub.serverhost.co.uk <-- is that a reverse DNS address for the server?
email.company.com just needs to be registered as an A record for the domain, then you'd purchase an SSL certificate reflecting email.company.com. (don't forget to create a certificate request that reflects the FQDN of email.company.com when you create the request).