Official DNS Guide • Privacy-Focused Business Email

Fastmail (Custom Domains) SPF Record Setup & Validator

Configure Fastmail custom domain SPF record (include:spf.messagingengine.com), triple CNAME DKIM keys (fm1/fm2/fm3), and DMARC enforcement.

Quick Answer • Exact Fastmail SPF Syntax

To authorize Fastmail (Custom Domains) to send emails on behalf of your domain, add include:spf.messagingengine.com to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:spf.messagingengine.com ~all.

Live Fastmail DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Fastmail (Custom Domains) Email Authentication

Fastmail is an independent, privacy-centric email suite supporting custom domains with triple CNAME-based automated DKIM key rotation and SPF authorization via messagingengine.com.

When Fastmail (Custom Domains) delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Fastmail (Custom Domains)'s IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Fastmail

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXT@v=spf1 include:spf.messagingengine.com ~all3600Fastmail SPF authorization.
CNAMEfm1._domainkeyfm1.yourdomain.com.dkim.fmhosted.com3600Fastmail rotating DKIM 1.
MX@in1-smtp.messagingengine.com3600Primary Fastmail MX.

Step-by-Step Setup Instructions

1

In Fastmail > Settings > Domains > Add Custom Domain.

2

Add the SPF TXT record: "v=spf1 include:spf.messagingengine.com ~all".

3

Add the 3 DKIM CNAME records (fm1._domainkey, fm2._domainkey, fm3._domainkey) pointing to messagingengine.com.

4

Add Fastmail MX records: in1-smtp.messagingengine.com (Priority 10) and in2-smtp.messagingengine.com (Priority 20).

5

Verify domain in Fastmail Settings.

Common Fastmail SPF Configuration Mistakes

× DKIM CNAME Trailing Dot Error

Cause: Omitting or adding extra periods in DNS provider CNAME targets.

Fix: Verify DNS provider syntax requirements.

Frequently Asked Questions

What is the SPF include mechanism for Fastmail?

Fastmail uses "include:spf.messagingengine.com".

Why does Fastmail use 3 DKIM CNAME records (fm1, fm2, fm3)?

Fastmail rotates DKIM keys across three CNAME records (fm1._domainkey, fm2._domainkey, fm3._domainkey) to support seamless, zero-disruption cryptographic key rotation. All three CNAMEs must be published simultaneously. Fastmail cycles the active signing key without requiring DNS updates.

What MX records does Fastmail custom domain require?

Fastmail requires two MX records: in1-smtp.messagingengine.com (Priority 10) and in2-smtp.messagingengine.com (Priority 20). Both must be present for reliable inbound mail delivery.

Is Fastmail a privacy-respecting email provider?

Fastmail is an Australian-based independent email provider, not affiliated with Google or Microsoft. It does not sell user data for advertising. Fastmail stores email on its own infrastructure and complies with Australian Privacy Act regulations. Custom domain users benefit from Fastmail's infrastructure while maintaining their own email identity.

What is the trailing dot issue with Fastmail DKIM CNAME records?

Some DNS providers require CNAME targets to end with a trailing dot (e.g. fm1.yourdomain.com.dkim.fmhosted.com.) to indicate an absolute FQDN. Others automatically append the trailing dot. Always check your DNS provider's documentation — omitting or double-adding the trailing dot causes CNAME resolution failure.

Can I use Fastmail alongside Google Workspace for my domain?

Not easily. MX records can only point to one mail provider at a time. Using Fastmail for custom domain email means your MX points to messagingengine.com, not Google. If you need both simultaneously, use Fastmail for personal/privacy mailboxes on a subdomain and keep the root domain on Google Workspace.