Fastmail Custom Domain SPF Record Configuration
To set up a fastmail spf record, you need to publish a specific TXT record at your domain registrar that includes Fastmail's sending servers using include:spf.messagingengine.com. When receiving mail servers check your domain's Sender Policy Framework (SPF), this entry tells them that Fastmail is fully authorized to send emails on your behalf. Without this configuration, your legitimate messages are much more likely to land in spam folders or be rejected outright by strict receiving filters.
Setting up email authentication for a custom domain can feel intimidating, but getting your SPF record right is critical for domain reputation and deliverability. Whether you are migrating an existing business domain or launching a fresh setup, this guide walks you through the exact syntax, registrar steps, troubleshooting techniques, and best practices to ensure your Fastmail integration is bulletproof.
Understanding How Fastmail SPF Works
SPF is a TXT record published in your Domain Name System (DNS) that lists all IP addresses and third-party services authorized to send email using your domain name. When a mail server receives an email claiming to be from you@example.com, it queries the DNS for example.com to retrieve its SPF record. If the sending server's IP address matches an entry in that record, the SPF check passes.
Because Fastmail manages a vast infrastructure of outbound mail servers, they do not ask you to list individual IP addresses. Instead, they provide an "include" mechanism. Fastmail maintains and updates their own internal list of sending IPs under their main policy domain.
The Correct Fastmail SPF Syntax
The standard, most basic Fastmail SPF record looks like this:
v=spf1 include:spf.messagingengine.com ~all
Let's break down each component of this string:
v=spf1: Defines the version of SPF being used. This must always be at the very beginning of the record.include:spf.messagingengine.com: Instructs the checking server to evaluate Fastmail's internal include mechanism and trust the IP addresses listed there.~all: The "SoftFail" mechanism. It tells receiving servers that any email sent from an IP address not listed in the record should be treated with suspicion, but not necessarily blocked instantly. (Alternatively,-alldenotes a HardFail, rejecting unauthorized mail outright, though~allis generally safer when you are first setting up or if you use multiple newsletter and CRM tools).
If you use multiple email services alongside Fastmail—such as a marketing platform or a transactional email provider—you must combine them into a single record rather than creating multiple TXT records, which violates the SPF specification.
How to Create and Add Your Fastmail SPF Record
Before you publish your record, it is wise to use the SPF Record Generator to automatically build, validate, and format your DNS entry without syntax errors. This free tool helps you combine Fastmail with other services cleanly.
Once you have your verified record string ready, follow these step-by-step instructions to publish it with your DNS host or domain registrar. Note that provider interfaces change frequently, so exact menu names may differ slightly across platforms.
Step-by-Step DNS Configuration
- Log into your domain registrar, DNS hosting provider, or Cloudflare account where your domain's zone file is managed.
- Navigate to the DNS Management, Zone Editor, or Advanced DNS settings section.
- Look for existing TXT records associated with your root domain (often represented as
@orexample.com). - Check if an SPF record (
v=spf1...) already exists. If you find an old one from a previous email provider, you must edit or replace it rather than adding a second one. - Create a new DNS record with the following parameters:
- Type:
TXT - Name / Host:
@(or leave blank, depending on your provider, to target the root domainexample.com) - Value / Content:
v=spf1 include:spf.messagingengine.com ~all - TTL (Time to Live): Set to
3600seconds (1 hour) or default.
- Type:
- Save the record.
Handling Subdomains and Multiple Providers
If you only send mail from your main domain (example.com), the root TXT record is sufficient. However, if you send transactional mail from a subdomain like mail.example.com, Fastmail or your other providers may require a separate SPF record specifically for that subdomain.
If you use other services like Google Workspace or Microsoft 365 alongside Fastmail (though rare for a single domain), you must merge the includes into one record:
v=spf1 include:spf.messagingengine.com include:_spf.google.com ~all
Be mindful of the 10-DNS-lookup limit enforced by the SPF specification. Every include, a, mx, or ptr mechanism that requires a separate DNS lookup counts toward this limit. Fastmail's include counts as one, but stacking too many third-party services will cause an SPF permanent error (permerror).
Verifying Your Fastmail SPF Configuration
After adding or updating your DNS record, you need to verify that it is propagating globally and returning the correct syntax. DNS changes can take anywhere from a few minutes to a few hours depending on your TTL settings.
Using Command Line Tools
You can query your domain's TXT records directly from your terminal using dig or nslookup.
dig example.com TXT
Sample successful output:
;; ANSWER SECTION:
example.com. 300 IN TXT "v=spf1 include:spf.messagingengine.com ~all"
If you are on Windows, you can use PowerShell:
Resolve-DnsName -Name example.com -Type TXT
Testing Mail Delivery and Authentication
To ensure receiving servers correctly evaluate your Fastmail SPF record, send a test email from your Fastmail account to an external auditing service such as Mail-tester.com or check the raw headers of an email sent to a secondary personal inbox (like Gmail).
In Gmail, open the message, click the three vertical dots, and select Show original. Look for the authentication block:
SPF: PASS with IP 192.0.2.1
DKIM: 'PASS' with domain example.com
DMARC: 'PASS'
Common Mistakes and How to Fix Them
Even experienced engineers occasionally trip over subtle SPF syntax rules. Avoid these common pitfalls to ensure uninterrupted email flow.
Having Multiple SPF Records
The Mistake: Creating two separate TXT records starting with v=spf1 because you want to add a second service.
The Fix: Merging all authorized senders into a single TXT record. Receiving servers will ignore multiple SPF records and return a permerror if they find more than one.
Typo in the Include Statement
The Mistake: Misspelling Fastmail's domain name, such as include:spf.fastmail.com or include:messagingengine.com.
The Fix: Fastmail's official include is strictly include:spf.messagingengine.com. Double-check your spelling against this exact string.
Forgetting DKIM and DMARC
The Mistake: Assuming SPF alone is enough for modern email security and high deliverability.
The Fix: SPF only checks the envelope sender domain. You should also configure Fastmail's custom DKIM (DomainKeys Identified Mail) CNAME records and set up a DMARC policy (e.g., v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com) to achieve comprehensive domain protection.
Quick Configuration Checklist
Review this fast checklist before closing out your DNS manager:
- Removed any legacy SPF records from previous email providers.
- Created a single TXT record on the root domain (
example.com). - Used the exact syntax
v=spf1 include:spf.messagingengine.com ~all(or added other required includes). - Checked that total DNS lookups remain well under the limit of 10.
- Verified global propagation using
digor an online DNS lookup tool. - Sent a test email to confirm
SPF: PASSin the raw message headers.