Set up SPF, DKIM and DMARC for Klaviyo

The exact SPF, DKIM and DMARC records Klaviyo needs, where to add them and how to check they pass and align, so Klaviyo mail reaches the inbox.

Updated September 30, 2026

Klaviyo mail passes DMARC only after you set up a branded sending domain in Settings > Domains. You pick a sending subdomain (like send.example.com) and add either four NS records for it (Dynamic routing) or three CNAMEs (Static routing: the subdomain plus two DKIM selectors such as km1._domainkey and km2._domainkey), a klaviyo-site-verification TXT record, and a DMARC record. No SPF include is needed.

Records at a glance

For a marketing domain using Static routing and the subdomain send:

HostTypeValue
sendCNAME
<value from Klaviyo>
Klaviyo’s example is 1.klaviyodns.com. Copy the value your account shows.
km1._domainkeyCNAME
<value from Klaviyo>
For example km1.domainkey.1.klaviyodns.com. Transactional domains use kt1, service domains ks1.
km2._domainkeyCNAME
<value from Klaviyo>
For example km2.domainkey.1.klaviyodns.com (kt2 or ks2 for other send types).
@TXT
klaviyo-site-verification=<your public API key>
Ownership check on the root domain. Add it as its own TXT record; don’t merge it into SPF.
_dmarcTXT
v=DMARC1; p=none; rua=mailto:<your report address>

With Dynamic routing (Klaviyo’s recommendation), you replace the CNAMEs with four NS records that delegate the sending subdomain to ns1.klaviyo.com through ns4.klaviyo.com, and Klaviyo manages that subdomain’s records for you. Use Static if your DNS host doesn’t support NS records. Service domains also need an MX record for inbound mail.

Set up SPF for Klaviyo

You don’t add Klaviyo to your SPF record. Klaviyo uses its own Return-Path domain on every message, and that domain already authorizes Klaviyo’s servers, so SPF passes by default. Your root SPF record stays as it is:

Your SPF record doesn’t change for Klaviyo
v=spf1 include:_spf.google.com -all

If you do edit SPF for other senders, update the existing record rather than adding a second one; two v=spf1 records on one name make SPF fail. DMARC Dojo’s hosted SPF avoids hand edits: you add senders in the dashboard and it keeps you under the 10-lookup limit.

Set up DKIM (branded sending domain)

  1. Click your company name in the bottom left of Klaviyo, select Settings, open the Domains tab and click Add Domain.
  2. Choose the send type (marketing, transactional or service). Use a different subdomain for each type, for example send, updates and support.
  3. Enter your root domain and a sending subdomain that isn’t already in use. Klaviyo suggests names like send or emails and advises against mail, which is often taken.
  4. Choose Dynamic (NS records) or Static (CNAME records) routing and add the records Klaviyo generates at your DNS host.
  5. Click Verify. When verification succeeds, click Activate on the domain row to start sending with it.
Send typeStatic DKIM selectors
Marketingkm1, km2
Transactionalkt1, kt2
Serviceks1, ks2
Static domains set up before send typeskl1, kl2 (unchanged)

The DKIM records are CNAMEs, so Klaviyo hosts and rotates the keys. For accounts with sending history, the domain must have been registered for at least 30 days. To confirm, send a test campaign to an outside mailbox and check for a DKIM-Signature with d= your domain and dkim=pass.

Make it pass DMARC (alignment)

Without a branded sending domain, Klaviyo signs with a shared Klaviyo domain and uses a Klaviyo Return-Path, so neither DKIM nor SPF aligns with your From address and DMARC fails. Klaviyo’s own documentation says a branded sending domain matching your sender address is required to be DMARC compliant.

  • DKIM aligns after the branded domain is active: Klaviyo signs with your domain in addition to its shared domain, and your signature is the one DMARC uses.
  • SPF doesn’t align, because the Return-Path stays on a Klaviyo domain. That’s fine: DMARC needs only one aligned pass. It does mean the DKIM records must stay in place.

Keep your From address on the root domain (hello@example.com, not hello@send.example.com), as Klaviyo asks. Relaxed alignment, the DMARC default, treats the branded subdomain as part of your organization’s domain. If you’re a bulk sender (Google’s threshold is 5,000 messages a day to Gmail), a branded domain isn’t optional. More in DMARC alignment explained.

Add DMARC

Starter DMARC record
v=DMARC1; p=none; rua=mailto:<your report address>

Klaviyo recommends at least v=DMARC1; p=none; on the root domain; adding rua gets you the reports. DMARC Dojo recognizes Klaviyo in DMARC reports, so campaigns show up as their own source and you can confirm they pass with DKIM alignment before moving to p=reject (how to get there).

Check your Klaviyo setup

Enter your root domain to check DKIM, SPF and DMARC, with a score out of 100 and the fixes to make.

Troubleshooting

  • Records don’t resolve on Cloudflare. Turn off proxying for Klaviyo’s records, and leave it off after setup.
  • Duplicated root domain. send.example.com became send.example.com.example.com. Enter only send (or km1._domainkey) at hosts that append the domain.
  • DNS host rejects the DKIM names. Some hosts don’t allow underscores. Ask them to add the records, or switch hosts; Klaviyo requires them.
  • Subdomain already in use. A website or another ESP already uses send. Pick a subdomain nothing else uses, since it can’t hold both sets of records.
  • Verified but not sending from it. The domain was verified but never activated. Click Activate on the domain row.

Frequently asked questions

Are Klaviyo’s DKIM selectors kl1 and kl2?

Only for Static domains set up before send types existed. New Static domains use km1 and km2 for marketing, kt1 and kt2 for transactional, and ks1 and ks2 for service mail. Dynamic domains are managed through NS records instead.

Should I choose Dynamic or Static routing?

Klaviyo recommends Dynamic (NS records) for the best sending performance, since Klaviyo then manages the subdomain’s records. Choose Static (CNAMEs) if your DNS host doesn’t support NS records on a subdomain.

Can I send from hello@send.example.com?

Klaviyo asks you to keep the subdomain out of the From address and send from the root domain, such as hello@example.com. The subdomain is for Klaviyo’s sending infrastructure.

Can I use the same branded subdomain in two Klaviyo accounts?

Yes, for the same brand. Each account generates its own klaviyo-site-verification TXT value, and you add all of them to your root domain.