Setup guide

SPF · DKIM · DMARC

Set up SPF, DKIM and DMARC on Klaviyo

Klaviyo authenticates a branded sending subdomain, not your whole domain — add the CNAMEs it generates, keep your existing SPF untouched, and own your DMARC.

Before you start

What Klaviyo needs from your DNS.

Klaviyo is a sending platform, not your mailbox host, so it authenticates on a branded sending subdomain rather than your root domain. You delegate that subdomain to Klaviyo with a handful of CNAME records, and Klaviyo publishes the SPF and DKIM for it on your behalf. This is the important difference from a mailbox provider: you do not paste a Klaviyo include into your root SPF, and you do not create a DKIM TXT by hand.

When you add a branded sending domain in Settings → Email → Domains, Klaviyo generates a sending-subdomain CNAME, two DKIM CNAMEs (km1 and km2 for a marketing domain), and a site-verification TXT. The targets are unique to your account, so copy them from the Klaviyo screen rather than from any guide — including this one. Once the CNAMEs resolve and you click Verify, the subdomain is delegated and Klaviyo handles SPF and DKIM under it automatically.

DMARC is the one record you own outright. It lives as a TXT on your root domain, is the same syntax for every sender, and is what ties Klaviyo's authenticated subdomain back to the domain your recipients see. Since Google and Yahoo began enforcing bulk-sender rules in February 2024, a branded sending domain plus a DMARC record is the baseline for reaching the inbox from Klaviyo.

The records to publish

Copy these into your DNS.

Add each record at your DNS provider — the company where your domain is registered, not Klaviyo. Then run the checker to confirm every one resolves.

SPF (sending subdomain) record

host  send type  CNAME

value generated by Klaviyo

Klaviyo generates the target (a klaviyodns.com host unique to your account) when you add the branded sending domain. This CNAME delegates the sending subdomain to Klaviyo, which then publishes SPF beneath it for you. Do not add a Klaviyo include to your root domain SPF — there is no public Klaviyo include, and guessing one breaks authentication. Your existing root SPF for your mailbox provider stays exactly as it is.

DKIM (key 1) record

host  km1._domainkey type  CNAME

value generated by Klaviyo

A CNAME, not a TXT. Klaviyo generates the target (km1.domainkey…klaviyodns.com) per account — copy it from the Domains screen. km1 and km2 are the selectors for a marketing sending domain; a transactional domain uses kt1 and kt2, a service domain ks1 and ks2. Match the selector Klaviyo shows you exactly.

DKIM (key 2) record

host  km2._domainkey type  CNAME

value generated by Klaviyo

The second DKIM CNAME, alongside km1. Both must resolve before Klaviyo will verify the domain. Add it exactly as generated — a missing or mistyped second key is a common reason verification stalls.

Domain verification record

host  @ type  TXT

value generated by Klaviyo

A klaviyo-site-verification=… TXT at the root that proves you control the domain. The value is unique to your account; copy it from the same Domains screen. This is separate from SPF and DMARC and does not replace either.

DMARC record

host  _dmarc type  TXT
v=DMARC1; p=none; rua=mailto:[email protected]

The one record you publish by hand, on your root domain. Start at p=none to watch alignment without affecting delivery, then raise to quarantine and reject once your reports show Klaviyo and every other legitimate sender aligning. If a DMARC record already exists, keep it — a domain may have only one.

Step by step

The whole setup, in order.

  1. 1 Add the branded sending domain in Klaviyo. In Klaviyo go to Settings → Email → Domains, click Add sending domain, and enter the subdomain you want to send from. Klaviyo then generates your CNAME records and a site-verification TXT. Leave this screen open — the targets are account-specific and you will copy them from here.
  2. 2 Publish the CNAME records at your DNS host. At your registrar or DNS provider — not in Klaviyo — add the sending-subdomain CNAME and both DKIM CNAMEs (km1 and km2) exactly as shown. These are CNAMEs, not TXT records. Do not touch your root SPF: Klaviyo publishes SPF under the delegated subdomain itself.
  3. 3 Add the site-verification TXT. Publish the klaviyo-site-verification TXT record at the root of your domain. It confirms ownership and is independent of your SPF and DMARC records.
  4. 4 Verify in Klaviyo. Once the records resolve, return to the Domains screen and click Verify. Klaviyo checks the CNAMEs and completes the delegation, at which point SPF and DKIM are active for the sending subdomain. Propagation can take up to 48 hours, so retry if it is not immediate.
  5. 5 Publish DMARC on your root domain. Add the _dmarc TXT record above at the root. Begin at p=none so nothing breaks while you read the reports, and point rua at an address you actually monitor. If you already run DMARC, leave the existing record in place.
  6. 6 Verify the full chain. Send a test campaign or run a check here to confirm the branded domain resolves, both DKIM selectors are found, SPF passes under the sending subdomain, and DMARC is aligned. Do not conclude anything has failed until DNS has fully propagated.

Where it goes wrong

The mistakes specific to Klaviyo.

Adding a Klaviyo include to root SPF There is no public Klaviyo SPF include to paste into your root domain. SPF is published by Klaviyo under the delegated sending subdomain. Inventing an include, or replacing your mailbox provider's SPF with one, breaks authentication.
Creating DKIM as a TXT record The km1 and km2 records are CNAMEs, not TXT. Pasting the target into a TXT record, or wrapping it in quotes, means DKIM never resolves. Publish them as CNAMEs pointing at the klaviyodns.com targets Klaviyo generated.
Using target values from a guide Every CNAME target and the site-verification value are unique to your account. Copy them from your own Domains screen in Klaviyo — values from any article, including examples, will not match your account and will fail to verify.
Only the first DKIM key published Both km1 and km2 must resolve before Klaviyo verifies the domain. Adding one and forgetting the second leaves verification stuck with no obvious error.
A registrar that appends the domain Some DNS panels add your domain to the host automatically. Entering send.yourdomain.com as the host can produce send.yourdomain.com.yourdomain.com. Enter only the subdomain label the panel expects.
Testing before propagation Verifying minutes after publishing shows a failure that is only DNS propagation. Klaviyo allows up to 48 hours for the records to be detected — give it time before troubleshooting.

Confirm it worked

Do not trust it until you have checked it.

DNS takes a few minutes to propagate. Once it has, run a full check: it reads all three records live, counts your SPF lookups, confirms the Klaviyo DKIM selector resolves, and grades your DMARC policy — the exact things that decide whether Gmail and Outlook trust your mail.

Common questions

About Klaviyo, specifically.

What is the Klaviyo SPF record? There is no Klaviyo SPF include you add to your root domain. When you set up a branded sending domain, you delegate a sending subdomain to Klaviyo with a CNAME, and Klaviyo publishes SPF under that subdomain for you. Your existing root SPF for your mailbox provider stays unchanged.
What is the Klaviyo DKIM selector? For a marketing sending domain the selectors are km1 and km2, published as CNAME records at km1._domainkey and km2._domainkey. Transactional domains use kt1 and kt2, service domains ks1 and ks2. The CNAME targets are generated per account in Settings → Email → Domains — copy them from there.
Why is my Klaviyo DKIM failing? Usually one of three things: you published the DKIM records as TXT instead of CNAME; you added only km1 and not km2; or your registrar appended your domain to the host so the record sits at the wrong name. Check both selectors resolve as CNAMEs and allow up to 48 hours for propagation.
Do I need a dedicated sending domain in Klaviyo? To authenticate with your own domain, yes. Without a branded sending domain, Klaviyo sends on its shared domain and your mail is not aligned to you. Adding the branded domain publishes SPF and DKIM under a subdomain you control, which is what DMARC and the bulk-sender rules expect.
Do I need DMARC for Klaviyo? Yes if you send in bulk to Gmail or Yahoo, which have required it since February 2024. Publish a _dmarc TXT on your root domain starting at p=none with a report address, then move to quarantine and reject once reports show Klaviyo and your other senders aligning. Keep any existing DMARC record — a domain may have only one.
Where do I add these records — in Klaviyo or at my registrar? Klaviyo generates the values, but every record is published at your DNS host: the registrar or provider that controls your domain's DNS. Add the CNAMEs and the verification TXT there, then return to Klaviyo and click Verify.

Set it once. Know it stays set.

A DKIM key rotates, a vendor changes its SPF, an IP gets listed — and your carefully-configured domain quietly breaks. Monitoring watches all of it and tells you the day it changes.