SPF · DKIM · DMARC
Set up SPF, DKIM and DMARC on Klaviyo
Klaviyo authenticates a branded sending subdomain, not your whole domain — add the CNAMEs it generates, keep your existing SPF untouched, and own your DMARC.
Before you start
What Klaviyo needs from your DNS.
Klaviyo is a sending platform, not your mailbox host, so it authenticates on a branded sending subdomain rather than your root domain. You delegate that subdomain to Klaviyo with a handful of CNAME records, and Klaviyo publishes the SPF and DKIM for it on your behalf. This is the important difference from a mailbox provider: you do not paste a Klaviyo include into your root SPF, and you do not create a DKIM TXT by hand.
When you add a branded sending domain in Settings → Email → Domains, Klaviyo generates a sending-subdomain CNAME, two DKIM CNAMEs (km1 and km2 for a marketing domain), and a site-verification TXT. The targets are unique to your account, so copy them from the Klaviyo screen rather than from any guide — including this one. Once the CNAMEs resolve and you click Verify, the subdomain is delegated and Klaviyo handles SPF and DKIM under it automatically.
DMARC is the one record you own outright. It lives as a TXT on your root domain, is the same syntax for every sender, and is what ties Klaviyo's authenticated subdomain back to the domain your recipients see. Since Google and Yahoo began enforcing bulk-sender rules in February 2024, a branded sending domain plus a DMARC record is the baseline for reaching the inbox from Klaviyo.
The records to publish
Copy these into your DNS.
Add each record at your DNS provider — the company where your domain is registered, not Klaviyo. Then run the checker to confirm every one resolves.
SPF (sending subdomain) record
value generated by Klaviyo
Klaviyo generates the target (a klaviyodns.com host unique to your account) when you add the branded sending domain. This CNAME delegates the sending subdomain to Klaviyo, which then publishes SPF beneath it for you. Do not add a Klaviyo include to your root domain SPF — there is no public Klaviyo include, and guessing one breaks authentication. Your existing root SPF for your mailbox provider stays exactly as it is.
DKIM (key 1) record
value generated by Klaviyo
A CNAME, not a TXT. Klaviyo generates the target (km1.domainkey…klaviyodns.com) per account — copy it from the Domains screen. km1 and km2 are the selectors for a marketing sending domain; a transactional domain uses kt1 and kt2, a service domain ks1 and ks2. Match the selector Klaviyo shows you exactly.
DKIM (key 2) record
value generated by Klaviyo
The second DKIM CNAME, alongside km1. Both must resolve before Klaviyo will verify the domain. Add it exactly as generated — a missing or mistyped second key is a common reason verification stalls.
Domain verification record
value generated by Klaviyo
A klaviyo-site-verification=… TXT at the root that proves you control the domain. The value is unique to your account; copy it from the same Domains screen. This is separate from SPF and DMARC and does not replace either.
DMARC record
v=DMARC1; p=none; rua=mailto:[email protected]
The one record you publish by hand, on your root domain. Start at p=none to watch alignment without affecting delivery, then raise to quarantine and reject once your reports show Klaviyo and every other legitimate sender aligning. If a DMARC record already exists, keep it — a domain may have only one.
Step by step
The whole setup, in order.
- 1 Add the branded sending domain in Klaviyo. In Klaviyo go to Settings → Email → Domains, click Add sending domain, and enter the subdomain you want to send from. Klaviyo then generates your CNAME records and a site-verification TXT. Leave this screen open — the targets are account-specific and you will copy them from here.
- 2 Publish the CNAME records at your DNS host. At your registrar or DNS provider — not in Klaviyo — add the sending-subdomain CNAME and both DKIM CNAMEs (km1 and km2) exactly as shown. These are CNAMEs, not TXT records. Do not touch your root SPF: Klaviyo publishes SPF under the delegated subdomain itself.
- 3 Add the site-verification TXT. Publish the klaviyo-site-verification TXT record at the root of your domain. It confirms ownership and is independent of your SPF and DMARC records.
- 4 Verify in Klaviyo. Once the records resolve, return to the Domains screen and click Verify. Klaviyo checks the CNAMEs and completes the delegation, at which point SPF and DKIM are active for the sending subdomain. Propagation can take up to 48 hours, so retry if it is not immediate.
- 5 Publish DMARC on your root domain. Add the _dmarc TXT record above at the root. Begin at p=none so nothing breaks while you read the reports, and point rua at an address you actually monitor. If you already run DMARC, leave the existing record in place.
- 6 Verify the full chain. Send a test campaign or run a check here to confirm the branded domain resolves, both DKIM selectors are found, SPF passes under the sending subdomain, and DMARC is aligned. Do not conclude anything has failed until DNS has fully propagated.
Where it goes wrong
The mistakes specific to Klaviyo.
Confirm it worked
Do not trust it until you have checked it.
DNS takes a few minutes to propagate. Once it has, run a full check: it reads all three records live, counts your SPF lookups, confirms the Klaviyo DKIM selector resolves, and grades your DMARC policy — the exact things that decide whether Gmail and Outlook trust your mail.
Common questions
About Klaviyo, specifically.
Set it once. Know it stays set.
A DKIM key rotates, a vendor changes its SPF, an IP gets listed — and your carefully-configured domain quietly breaks. Monitoring watches all of it and tells you the day it changes.