DomainCanary Start free

SPF and DKIM by provider

SPF record for Klaviyo

Last updated 7 Sep 2026

Klaviyo sends ecommerce campaigns and flows. Here is what to publish so it can do that as your domain, and what has to line up before DMARC will pass.

What to add. No include on your root SPF record. Klaviyo generates the records for you.

What signs your mail. DKIM records Klaviyo generates for your account.

You set up the dedicated sending domain, then leave the campaign's From address on the root domain where it does not match, or worse, on a free mailbox address.

The SPF record

There is nothing to add to your root SPF record. Klaviyo authenticates by taking over a sending subdomain you choose, something like send.example.com, through CNAME records. The SPF record that gets evaluated is the one Klaviyo publishes on that subdomain, which keeps your own ten-lookup budget free.

Klaviyo's DNS troubleshooting page says the same, and I checked it on 2026-09-04: you usually need no SPF record for Klaviyo, because it sets its own return path on every message.

Until you do this, Klaviyo sends from its shared infrastructure with its own domain in the envelope and its own signing domain, and nothing aligns with you.

Whatever you end up publishing, count the lookups afterwards. SPF allows ten DNS-querying mechanisms across the whole nested chain, and going over turns the record into a permerror that authorizes nothing. Our free SPF checker resolves the chain and gives you the number.

DKIM

The dedicated sending domain setup gives you a small set of CNAMEs, including _domainkey entries under the sending subdomain, with selectors Klaviyo generates. Copy them from the Klaviyo screen exactly, including the subdomain part, which is the piece people trim off by accident.

Klaviyo offers two routings for that subdomain. The static one is up to three CNAMEs, and the DKIM selector prefixes follow what the domain is for: km1 and km2 for marketing, kt1 and kt2 for transactional, ks1 and ks2 for service. The dynamic one delegates the subdomain to Klaviyo's own nameservers with four NS records, and then there is no DKIM record of yours to publish at all.

Either way there is one TXT record proving you own the domain, whose value starts klaviyo-site-verification=. Publish it with the rest.

DMARC alignment with Klaviyo

DMARC passes when SPF or DKIM passes and the domain it authenticated matches the domain in your visible From address. A provider can pass both checks for its own domain and leave you failing. These are the Klaviyo specifics:

  • Relaxed DMARC alignment means mail signed for send.example.com aligns with a From address at example.com. Strict alignment breaks it. Leave adkim alone unless you know why you are changing it.
  • A dedicated sending domain starts with no reputation. Ramp volume over a couple of weeks rather than moving a hundred thousand sends onto it in one night.
  • Klaviyo's shared sending is fine for testing and useless for DMARC. Do not judge your alignment from a test send made before the CNAMEs went live.

The general case is covered in alignment, explained, and the header you read to prove it is on the dmarc=fail page.

Verify it

Substitute your domain, and run these after the TTL on anything you replaced has expired:

dig +short TXT example.com dig +short TXT _dmarc.example.com

Then send one message through Klaviyo to a Gmail address you control, open Show original, and look for dkim=pass with your domain in header.i. That single check is worth more than any number of DNS lookups, because it tests the thing receivers actually do.

Our SPF checker gives you the lookup count, the DKIM checker confirms a selector resolves and the key is long enough, and the DMARC checker reads your policy back to you. All three are free and none of them ask for an account.

Values here were checked against Klaviyo's own documentation, at Klaviyo help center. Providers change DNS requirements without much announcement, so if their screen disagrees with this page, believe their screen and tell us.

A record can read correctly and still fail alignment once real mail moves through it. Receivers write that verdict into the reports they send. We read them for you, and paid plans email you the same day one names a new sender that failed, instead of holding it for Monday. See whether this sender passes. Your first domain is free.

Do Klaviyo's messages pass as your domain?

SPF, DKIM and DMARC in one pass, read the way receivers read them.

Free · No signup · The result names what to change