Fastmail SPF, DKIM and DMARC check
Enter the domain you send from with Fastmail. We check the SPF include, the Fastmail DKIM key, your DMARC policy and MX records, and tell you what is missing.
What Fastmail expects
SPF
Add include:spf.messagingengine.com to your single SPF record, for example: v=spf1 include:spf.messagingengine.com ~all
Costs 1 of your 10 SPF lookups (checked October 2026).
Build a combined SPF record if you send from more than one service.
DKIM
Selectors we look for: fm1fm2fm3
Fastmail publishes DKIM as three CNAMEs: fm1, fm2 and fm3._domainkey.yourdomain, pointing at fm1.yourdomain.dkim.fmhosted.com and so on. The exact values are under Settings > Domains > your domain > DNS records.
DMARC
DMARC is set on your domain, not in Fastmail. If you have none, start with v=DMARC1; p=none; rua=mailto:dmarc@yourdomain.com and tighten it once reports look clean. Generate one.
MX
in1-smtp.messagingengine.com (10) and in2-smtp.messagingengine.com (20).
Values come from Fastmail’s public setup documentation and can change. The Fastmail settings always shows the exact records for your account. Use those if they differ from this page.
Keep it working after setup
The usual failures come later: a second SPF record added for a new tool, a DKIM CNAME lost in a DNS move, a DMARC record deleted with an old zone. SenderBeacon checks twice a day and emails you in plain English. From $9/month, 14-day free trial, no card.
Start free trialQuestions
How long until Fastmail DNS changes show up?
Usually minutes, sometimes up to an hour, depending on the TTL on your records and your DNS host. Re-run the check after publishing.
Why does the check say DKIM is missing when Fastmail says it is verified?
Most often the record went on the wrong host (for example _domainkey.yourdomain.com.yourdomain.com, because the DNS host appended the domain twice), or you are checking a different domain or subdomain than the one you send from.