Fastmail Review: A Deep Dive into Privacy, Security, and Sovereignty

Fastmail isn't interested in feature trends or marketing hype. A deep dive into their security architecture, EU data residency, tamper-proof email retention, and why keeping AI out of the inbox is a major win for authentic communication.

Paul O'Brien
– 9 min read

A focused deep dive into data residency, security architecture, corporate resilience, and why keeping AI out of the inbox is a feature, not a bug.

Rather than going on an endless search for another email provider to review, I decided to take another look at one of the true staples of the space: Fastmail.

Regular readers might remember that I published a general review of Fastmail last year. But while that post covered the user experience and feature set, this follow-up isn't just another surface-level overview—there are plenty of those already.

Instead, this article is a focused deep dive into the company itself: their security architecture, privacy ethos, data sovereignty, and corporate resilience.

To summarise this updated review right off the bat: Fastmail isn't obsessed with chasing endless feature trends or pushing non-stop marketing hype. They’ve never tried to reinvent the wheel. Instead, they consistently deliver one of the fastest, most feature-rich, stable, and cost-effective email services on the market.

Before we dive in, let me address an obvious question: If I rate Fastmail so highly, why is my primary email currently on Google Workspace?

The answer comes down to one simple thing: cost. Not because Fastmail isn't worth every penny—it absolutely is. Rather, I needed to sign up for Google Workspace to get enhanced access to Gemini AI (including NotebookLM) along with a few other tools. Since email came bundled with the subscription, I decided to take Gmail for business for another test drive and migrated my domain over.

That left my Fastmail account redundant, and since I only use my own custom domain rather than a @fastmail.com address, I closed it to save a few extra pounds a month.

In all honesty, as much as I’m enjoying Gmail and its deep integration with the rest of the Google ecosystem, I really miss the raw speed and clean simplicity of Fastmail. My guess? It’s only a matter of time before I end up migrating right back. (On the plus side, keep an eye out for an upcoming deep dive into my experience using Gmail within Google Workspace!)

Now, onto the part you actually came here for. Get comfortable, grab a hot drink of your choice, and enjoy the review.

Behind the Name: Who Fastmail Really Is

The name "Fastmail" doesn't quite do justice to what the service has actually built, nor does it capture the ethos behind the company.

Headquartered in Melbourne, Australia, Fastmail was established back in 1999 and is a privately owned, independent business. While they don't publicly disclose exact subscriber figures, industry estimates put their active paying customer base at around 400,000 to 500,000 subscribers, representing between 1 million and 2 million managed email accounts globally.

From a corporate resilience and tech strategy perspective, their structure aligns perfectly with what I look for in a software provider. Led by an experienced team alongside CEO Bron Gondwana, founder Rob Mueller remains actively involved as CTO. Having founder leadership still at the helm is a huge positive—it ensures the core engineering principles and privacy ethos aren't lost to board member pressure or short-sighted shareholder demands.

Because they rely on a simple subscription model rather than venture capital or ad-revenue targets, Fastmail isn't under pressure to monetise user data, force unwanted feature pivots, or chase tech trends. Their business model keeps their goals completely aligned with their users: delivering a stable, private, and secure platform that simply works.

Refreshing Transparency

As a business, their transparency is incredibly refreshing. They don't hide behind pages of dense legal jargon; they deliver their security and privacy policies clearly, and they openly publish their Data Transparency Report for anyone to inspect.

Having been a business owner specialising in SaaS products for over 25 years, one of my core values has always been honesty. That sounds like it should be a given in business—until you start examining some of the major tech corporations and realise true honesty is a rarity.

Another thing you realise very quickly with Fastmail is that they aren't aggressively trying to compete with anyone. They don't waste time running aggressive smear campaigns or shouting, "We're better than Google because we don't do X, Y, or Z." Don't get me wrong, comparison charts can be helpful, but Fastmail simply lets their service sell itself. They know exactly who they are, what they stand for, and what their unique value is in the market.

With a proven business model, competitive pricing, and a stellar reputation that goes far beyond a flashy feature list, they just focus on keeping their users happy. You only have to read a few of their client testimonials to see that their customers genuinely love the platform.

Choosing Your Data Residency: The EU Region

Fastmail recently expanded its infrastructure by launching an EU Data Region, allowing users to host their primary email, calendar, and file data on dedicated servers in Amsterdam rather than exclusively in the United States.

Here is why this update is a significant move for privacy-conscious users and businesses:

  • Data Residency & Compliance: European businesses and privacy-focused users bound by strict GDPR guidelines or internal compliance rules can now ensure their primary data resides within EU borders.
  • Faster Performance: Routing daily app traffic directly through local servers in Amsterdam lowers latency, leading to faster load times for users in and around Europe.
  • Hardware-Level Control: Rather than renting space from third-party hyperscalers like AWS or Google Cloud, Fastmail deployed its own physical hardware in an Amsterdam co-location facility—preventing third-party cloud access to user data.
  • Zero Extra Cost: Unlike many privacy and enterprise email providers that charge a premium for custom data hosting locations, Fastmail includes the EU region option at no additional charge.

(Note on legal jurisdiction: While physical primary storage moves to Europe, Fastmail remains an Australian entity, and off-site disaster recovery backups temporarily replicate to US servers.)

Data Security, Replication, and Physical Control

Beyond location choices, Fastmail outlines a strict, hands-on approach to how user data is stored, backed up, and protected. For starters, they completely avoid "cloud renting." Fastmail doesn't rely on hyperscale cloud providers like AWS or Google Cloud; instead, their in-house team directly manages their own physical hardware, keeping all data encrypted at rest inside locked server racks.

To safeguard availability, they rely on triple data replication. Fastmail keeps at least two copies of every email on separate servers within your primary location (such as Amsterdam or the US), alongside a third live replica in a geographically separate region for instant failover. On top of this real-time sync, they maintain automated off-site backups completely independent of the live system. These point-in-time recovery snapshots are taken every few hours for every account and are currently centralised in their Philadelphia facility to ensure seamless disaster recovery.

Data Transparency: Proof Over Promises

While many email providers make grand claims about privacy, Fastmail backs theirs up with hard data through their public Data Transparency Report.

Their approach centres on strict legal scrutiny: Fastmail explicitly rejects informal or direct overseas demands, requiring every law enforcement request to strictly meet Australian legal standards before being deemed valid.

Because Fastmail is a paid subscription service rather than a free inbox provider, it naturally attracts far fewer bad actors—processing only a handful of valid requests globally each year (such as just 16 in 2024).

They break down every request to distinguish between basic subscriber metadata and actual stored email content, actively pushing back against overly broad or improperly formed fishing expeditions. Instead of hiding behind vague corporate language, Fastmail publishes clear, transparent metrics that explain exactly how foreign requests (like US Cloud Act inquiries) are vetted through official mutual assistance channels.

Privacy & Security in Practice

Beyond choosing your data residency, setting up retention policies, and relying on multi-layer backups, Fastmail offers a comprehensive security stack. Account protection includes passkeys, two-factor authentication (2FA), and secondary password prompts for sensitive administrative actions.

Your primary email address effectively acts as the master password to your digital life—governing access to financial records, healthcare portals, and online services. Fastmail safeguards this entry point with robust encryption both in transit (utilising TLS 1.3 and Perfect Forward Secrecy) and at rest on physical disks housed in locked server racks. They also employ Strict Transport Security (HSTS) headers to block man-in-the-middle attacks, alongside a strict Content Security Policy that ensures only verified Fastmail code runs in your browser.

Smart Privacy Built Into the Inbox

When you open an email containing remote images, standard email providers often allow the sender to track your physical location, identify your device type, and cross-reference your online activity. Fastmail stops this tracking by default, anonymously proxying all remote images on your behalf before they ever reach your device.

Similarly, sharing your main email address across every online account allows advertising networks to build detailed profiles of your habits. Fastmail addresses this through built-in Masked Email integration. You can generate a unique, throwaway email address for every service or signup, keeping your real address private and preventing data brokers from linking your accounts together.

Pragmatic Security and Data Access

Privacy policies are only as strong as the internal culture enforcing them. At Fastmail, employee access to customer data operates strictly on the principle of least privilege. An engineer cannot simply view a user’s inbox; accessing personal data requires explicit permission, a justified support ticket, and an audited access log. In their 25-year history, Fastmail has never had an incident of employee data misuse—a record backed by strict contractual penalties up to termination and legal prosecution.

Fastmail’s stance on end-to-end encryption (E2EE) is refreshingly pragmatic:

Why Fastmail doesn't offer native E2EE in its web app: True E2EE requires both sender and receiver to exchange cryptographic keys securely—an infrastructure that largely doesn't exist across the broader email ecosystem. Implementing E2EE inside a web client adds negligible security against a compromised server (since the server itself serves the decryption code) while breaking essential features like server-side full-text search, inbox message previews, and automated spam filtering. Fastmail fully supports PGP and S/MIME through third-party desktop clients if you need it, but they rightly point out that if your threat model demands absolute end-to-end secrecy, you should be using specialised tools like Signal rather than standard email.

Granular Spam Control and Privacy Advocacy

Spam filtering on Fastmail avoids aggressive false positives that cause important messages to disappear. Every incoming message is scored against customisable criteria, offering presets alongside granular custom controls to fine-tune how strict your filter needs to be.

Finally, Fastmail’s commitment to privacy extends beyond their own software code. They actively partner with and support digital rights organisations—including Electronic Frontiers Australia, Digital Rights Watch, the Australian Privacy Foundation, and the Communications Alliance—to advocate for better consumer privacy laws and promote ethical tech practices globally.

Professional Email Retention: A Corporate Resilience Essential

Fastmail also offers a Professional Email Retention Archive—and looking at this through my Corporate Resilience and Business Continuity (BC) hat, it’s a feature I’m a huge fan of. ⭐⭐⭐⭐⭐

Unlike a standard archive folder that an individual user can clear or modify, this feature automatically captures a tamper-proof, read-only copy of every single incoming and outgoing email behind the scenes.

  • Why It Matters for Resilience & BC: From a business continuity perspective, data integrity and disaster recovery are paramount. If a rogue employee attempts to wipe their inbox, or if an account is compromised during an incident, your operational paper trail remains completely intact.
  • Regulatory Compliance: Essential for businesses that must meet strict auditing, legal discovery (eDiscovery), or regulatory requirements (such as SEC, FINRA, or GDPR mandates).
  • Tamper-Evident Security: Access is restricted strictly to account administrators, and turning the feature on or off automatically generates an alert, preventing silent manipulation.
  • No Hidden Premium: Fastmail includes this directly in their Professional/Business plans without charging an extra per-gigabyte premium—a massive plus for IT budgeting.

No AI In My Email, Thank You Very Much

First off, apologies in advance to my trusty AI assistant—without whom my grammar in these posts would render half of them unreadable. But in my humble opinion, AI has no welcome place inside an email app.

Pitching an integrated AI bot that rewrites your messages, suggests canned replies, and summarises your inbox as a core USP feels like pure marketing hype. I need built-in AI in my email about as much as I need an itchy foot while driving down the motorway.

The fact that Fastmail hasn't crammed an AI assistant into the inbox is a massive relief—especially when so many competitors don't even give you the option to toggle it off. (For context: Fastmail keeps their core app entirely human, offering only an opt-in connector for developers who want to attach external tools, leaving the inbox completely clean by default).

Email should be personal—warts and all. Sending an email isn't the same as publishing a polished blog post, drafting a formal legal letter, or proofreading a thesis, and I wish people would stop treating it like one. When I send a message, I want my actual voice to shine through. I want the receiver to know I wrote it personally, not generated a corporate canned response.

So thank you, Fastmail, for steering clear of forced inbox AI and keeping email raw and authentic.

The Bottom Line

Fastmail remains the gold standard for anyone who values speed, independence, and genuine data privacy over marketing gimmicks. In an industry increasingly dominated by forced AI features, aggressive ad tracking, and opaque data practices, Fastmail’s straightforward approach—owning their infrastructure, offering true EU data residency, enforcing strict legal vetting, and keeping the inbox human—is a breath of fresh air. Whether you're looking to safeguard your personal correspondence or protect your business continuity with tamper-proof archiving, Fastmail proves that paid, independent software is worth every single penny.


CTA Image

Try Fastmail & Save 10% on Your First Year

If you're ready to take back control of your inbox, you can try Fastmail risk-free with a 30-day trial. If you decide to stay, signing up through my referral link below gives you 10% off your subscription for your entire first year

Signup

(Full transparency: This is an affiliate link. If you subscribe using it, you get a 10% discount for a full year, and I receive a referral credit at no extra cost to you. I only recommend services I personally use and trust.)