Migrate Fastmail to JustEmails: Full IMAP Migration Guide
Fastmail migration with imapsync, alias mapping, and DNS cutover.
Fastmail migration with imapsync, alias mapping, and DNS cutover.
The renewal email from Fastmail landed on a Wednesday. Five users across three domains. The math: $6/user/month times twelve months times five users. $360/year for email.
Not outrageous. But then I looked at the trajectory. We'd started with one domain and one user three years ago. $72/year, totally reasonable. Then the second domain. Then contractors. Then the third domain with a couple more addresses. Every addition bumped the bill. And now I'm staring at $360/year wondering how much it'll be in another two years.
Look, I'll say this upfront: Fastmail is genuinely excellent. The webmail is probably the best browser-based email client that exists. The keyboard shortcuts work like a native app. The calendar integration is polished. If you're a solo power user with one domain, leaving Fastmail probably doesn't make sense for you. Stay.
But if you're like us — managing email across multiple domains, adding team members, watching that per-user bill creep up — the economics eventually flip. That's when flat-fee makes sense.
We're the JustEmails team, part of Velocity Digital Labs. We built JustEmails specifically for people who outgrew per-user pricing — the same problem that drives users to compare JustEmails vs Google Workspace. This is the migration guide I wish existed when we made the switch ourselves.
All your Fastmail email history moved to JustEmails. MX records pointing to our servers. SPF, DKIM, and DMARC configured and passing. Your aliases recreated. Mail clients working with new server settings.
One thing you won't have: Fastmail's webmail polish. And calendar/contacts if you were using those. We're email-only — different scope, intentionally. If you rely heavily on Fastmail's calendar or their masked email feature, factor that into your decision before starting.
Before you begin, make sure you have:
That last one catches people. Fastmail requires app-specific passwords when two-factor auth is on. Go to Settings → Privacy & Security → App Passwords → Create New. Do this before day one.
I spent an embarrassing amount of time troubleshooting "authentication failed" before remembering this.
Plan the first fortnight's outbound volume while you're at it. Sends are capped per account per day — 20/day for the first week, 200/day in the second, 500/day from day 15 on — with mailbox sends and API sends counted against the same number. Warm-up runs from domain verification rather than signup, so a domain added to a long-standing account starts back at the bottom of that ramp. The imapsync import isn't affected; this is about mail you send after the cutover.
Before touching anything, document what you have. Fastmail built one of the more elaborate alias systems around — standard aliases, plus masked email addresses, plus wildcard subdomain addressing. You can't migrate these automatically.
In Fastmail, go to Settings → Sending Identities. Screenshot or export this list. Then check Settings → Rules to see any forwarding or filtering rules you've set up.
Create a spreadsheet or text file:
Primary addresses:
- alex@mydomain.com
- hello@seconddomain.com
- support@thirddomain.com
Aliases:
- team@mydomain.com → forwards to alex@mydomain.com
- info@seconddomain.com → alias for hello@seconddomain.com
Masked emails (if using):
- random123@mydomain.fastmail.com → used for newsletter signups
You'll recreate these in JustEmails later. The masked email feature specifically doesn't translate — JustEmails supports catch-all addresses which accomplish something similar, but not the disposable masked address workflow Fastmail pioneered.
Log into JustEmails. Add your domains — verification is a TXT record, usually propagates in under five minutes.
Create a mailbox for every primary address you're migrating. Match them exactly: if alex@mydomain.com exists in Fastmail, create alex@mydomain.com in JustEmails.
JustEmails includes unlimited mailboxes on the $49/year plan. Create all of them now — primary addresses, role accounts (support@, billing@, hello@), everything.
Write down the IMAP credentials for each mailbox. You'll need these for imapsync.
Don't touch MX records yet. We're not cutting over today.
imapsync copies mail between IMAP servers. It preserves folders, dates, read/unread flags, everything. This is the workhorse.
On Ubuntu/Debian:
sudo apt update && sudo apt install imapsync
On macOS with Homebrew:
brew install imapsync
Verify it's working:
imapsync --version
Fastmail's IMAP server is imap.fastmail.com. Here's the command template:
imapsync \
--host1 imap.fastmail.com --port1 993 --ssl1 \
--user1 "alex@mydomain.com" --password1 "fastmail-app-password" \
--host2 mail.justemails.app --port2 993 --ssl2 \
--user2 "alex@mydomain.com" --password2 "justemails-password" \
--automap
Run this for each mailbox. For multiple accounts, a CSV and bash loop:
while IFS=, read -r user fmpass jpass; do
imapsync \
--host1 imap.fastmail.com --port1 993 --ssl1 \
--user1 "$user" --password1 "$fmpass" \
--host2 mail.justemails.app --port2 993 --ssl2 \
--user2 "$user" --password2 "$jpass" \
--automap
done < users.csv
CSV format: email,fastmail-app-password,justemails-password. One row per mailbox.
First sync takes time. A mailbox with 10GB of mail took us about three hours. Let it run overnight if needed.
Fair warning: I once closed my laptop during a sync thinking it would continue. It did not. imapsync is resumable — if it crashes, run the same command again and it picks up where it stopped. But "resumable" doesn't mean "runs in the background while you sleep." Lesson learned.
(You can also use Thunderbird or Apple Mail to export then import. Works fine for one or two mailboxes. For five or more, imapsync is faster.)
Boring but critical.
Your MX records have a TTL — probably 3600 (1 hour) or longer. When you change MX records, some servers will keep using cached values until the TTL expires. That means mail going to Fastmail after you thought you'd cut over.
In your DNS panel:
Now wait. At least as long as your old TTL — ideally 24 hours. The old TTL needs to expire everywhere before the new short TTL takes effect.
I know you want to skip this. Don't. Skipping this step is how you end up with mail disappearing into Fastmail for hours after cutover. Ask me how I know. (Actually don't. It was a bad week.)
While waiting, grab the JustEmails DNS records from your domain settings — MX, SPF, DKIM. You'll need them tomorrow.
Deep breath.
This is the day.
Delete your Fastmail MX records. They look something like:
in1-smtp.messagingengine.com (priority 10)
in2-smtp.messagingengine.com (priority 20)
Add the JustEmails MX record from your dashboard. Note that Fastmail's two-record shape doesn't carry over — there is one JustEmails MX host, not a pair:
mail1.justemails.app (priority 10)
Check the exact value in your JustEmails domain settings before you save.
Your SPF record probably includes Fastmail. It looks something like:
v=spf1 include:spf.messagingengine.com ~all
Change it to:
v=spf1 a:mail1.justemails.app ~all
Note the shape change: Fastmail authorises its senders through an include:, we do it with an a: mechanism that authorises whatever IP mail1.justemails.app resolves to. There is no JustEmails include to point at.
If you have other senders (Mailchimp, your app's transactional email), keep their includes and drop only Fastmail's — for example v=spf1 a:mail1.justemails.app include:servers.mcsv.net ~all.
For DKIM, add the new records from JustEmails. They're CNAME records:
je1._domainkey.mydomain.com → je1.dkim.justemails.app
je2._domainkey.mydomain.com → je2.dkim.justemails.app
Delete the old Fastmail DKIM records (fm1._domainkey, fm2._domainkey, fm3._domainkey). Keeping dead DKIM records doesn't break anything, but clutters your DNS.
Remember that alias list from Step 1? Now's when you use it.
In JustEmails, go to your domain settings and add aliases. For each alias, specify where it should deliver — the primary mailbox that should receive the mail.
For catch-all (receiving mail to any address at your domain), enable it in domain settings. This partially replaces Fastmail's masked email feature — any address works, they all land in one inbox.
If you had complex routing rules in Fastmail (messages to sales@ get forwarded to three people, etc.), you'll need to recreate those as forwarding rules or distribution lists in JustEmails. The interface is different, but the capability exists.
Don't trust "it looks fine."
Test it.
https://mxtoolbox.com/SuperTool.aspx?action=mx:mydomain.com
You should see a single JustEmails MX row at priority 10 — one is the expected result here, not a sign that something didn't save. Check SPF and DKIM too. Any warnings should be about propagation timing, not configuration.
Send test emails from an external account (personal Gmail, Outlook.com) to your migrated addresses. Verify they arrive in JustEmails, not Fastmail.
Send from your JustEmails addresses to external accounts. Check that they land in inbox, not spam. If you're getting spam-foldered, check SPF/DKIM alignment — our DMARC guide covers debugging this.
Mail that arrived at Fastmail between your initial sync and the MX cutover is still sitting in Fastmail. Run imapsync again for each mailbox:
imapsync \
--host1 imap.fastmail.com --port1 993 --ssl1 \
--user1 "alex@mydomain.com" --password1 "fastmail-app-password" \
--host2 mail.justemails.app --port2 993 --ssl2 \
--user2 "alex@mydomain.com" --password2 "justemails-password" \
--automap
Same command as before. imapsync only copies new or changed messages — won't duplicate what's already there. This delta sync is usually fast. Minutes, not hours.
Your team's mail clients need new server settings:
Incoming (IMAP):
Outgoing (SMTP):
Thunderbird, Apple Mail, Outlook, mobile apps — all of them. Budget 10-15 minutes per person for hand-holding. Some folks figure it out instantly. Others need screenshots of every step. One of our contractors somehow added the account four times. Still not sure how.
If you were using Fastmail's native mobile apps, you'll switch to third-party clients — Spark, Edison, or the built-in iOS/Android mail apps. JustEmails works with standard IMAP clients; we don't have our own mobile app. (The native apps are one of the genuine losses in this migration. Fastmail's mobile experience is polished.)
"Authentication failed" on imapsync
Your Fastmail app password is wrong or expired. Go to Fastmail Settings → Privacy & Security → App Passwords and generate a new one. Make sure 2FA is actually enabled — if it's not, use your regular password instead.
Mail still arriving at Fastmail after cutover
DNS propagation isn't complete. If your old TTL was high, some servers are still caching. Keep Fastmail active and run delta syncs daily until traffic stops. This can take 48-72 hours in stubborn cases.
Honestly, this part frustrated me more than anything else in the whole migration. You do everything right, and some ancient mail server in who-knows-where keeps sending to Fastmail for three days. Nothing you can do but wait.
DKIM fails validation
Wait 15-60 minutes for CNAME propagation. If it still fails, check the record names — the underscore matters. It's je1._domainkey.mydomain.com, not je1.domainkey.mydomain.com.
Aliases not receiving mail
Check that the alias is pointing to a valid primary mailbox. In JustEmails, aliases must route somewhere — they're not standalone addresses. If you created an alias before creating its target mailbox, it won't work.
Folder names are different
Fastmail uses standard IMAP folders, so mapping is usually clean. But if you had custom folder names with special characters, they might get sanitized. Check after sync and rename if needed.
I'll be direct: you're giving up webmail quality. Fastmail's browser interface is best-in-class — keyboard shortcuts, fast search, conversation threading that works. JustEmails has functional webmail. It does the job. It won't win design awards.
You're also losing native calendar and contacts if you were using those. JustEmails is email-only. Export your Fastmail calendar to ICS and import it elsewhere (Google Calendar, Apple Calendar, whatever). Same for contacts — export as vCard or CSV.
And the masked email feature? Gone. JustEmails has catch-all addresses which serve some of the same purpose, but the disposable alias workflow Fastmail offers doesn't exist here.
So why migrate? Because $49/year flat beats $360/year for five users across three domains. Because unlimited mailboxes means adding team members doesn't bump the bill. Because the transactional API bundled into JustEmails means one less vendor to manage. For agency owners dealing with client domains, see our Google Workspace migration guide and the multi-domain pricing analysis.
If you're a solo power user who lives in Fastmail's webmail? Stay. Genuinely. The per-user premium is worth it for you.
If you've outgrown that model? Welcome.
Don't cancel Fastmail immediately. Some slow mail servers might still deliver there. Keep Fastmail active (downgrade to the cheapest plan if you want) and run imapsync weekly for a month.
At day 30, log into Fastmail, verify no new mail is arriving, revoke those app passwords, and cancel. For ongoing domain health monitoring, check out our custom domain email setup guide.
Questions? support@justemails.app. We answer email. (Obviously.) If you're comparing options before committing, our Fastmail comparison post covers the feature-by-feature breakdown. And for privacy-first web analytics to pair with your email, JustAnalytics handles tracking without the baggage. Click fraud eating your ad budget while you migrate? ClickzProtect catches bots before they drain your spend.
Only if you have two-factor authentication enabled — which you probably do. Go to Fastmail Settings → Privacy & Security → App Passwords and create one for the migration. Label it something obvious like 'imapsync-migration' so you remember to revoke it afterward. If 2FA isn't on, your regular password works, but honestly you should enable 2FA anyway.
Plan for 3-4 days. Day 1 is account setup and initial IMAP sync. Day 2 is TTL lowering. Day 3 is the MX cutover and SPF/DKIM rotation. Day 4 is delta sync and verification. Hands-on work is maybe 2-3 hours total — the rest is waiting for DNS propagation and catching any stragglers.
Yes — and that's the honest tradeoff. Fastmail's webmail is probably the best browser-based email interface that exists. JustEmails has functional webmail, but we're not trying to match Fastmail's polish. If you live in webmail 8 hours a day and that experience matters deeply, think hard about whether the cost savings justify the UX downgrade. If you mainly use desktop clients like Thunderbird or Apple Mail, you won't notice much difference.
You'll need to recreate them manually. Fastmail built out an elaborate alias system including masked emails for privacy. JustEmails supports unlimited aliases and catch-all addresses, but the masked email feature specifically doesn't exist. Export your alias list from Fastmail before migrating, then set up equivalent aliases in JustEmails. Most aliases map directly; masked emails you'll need to decide whether to keep forwarding from Fastmail briefly or replace entirely.
Unlimited custom domain email hosting for $49/year flat — unlimited domains, unlimited mailboxes, 10 GB storage, full IMAP/SMTP. Built for agencies, freelancers, and anyone managing email across more than one domain.