What's especially frustrating is that Fastmail have a special opaque sender header that only they can interpret, and they put a little "verified" icon on email that actually comes from them. So it's a vulnerability if I impersonate them, but not any other Fastmail user. Sigh. I'm a happy FM user, apart from that. But I'm going to keep bringing it up until they do something about it. At least let me blacklist my domain from being used by other accounts jfc.