Klaviyo: SPF, DKIM & DMARC Setup Guide
Klaviyo requires a dedicated sending subdomain and DKIM authentication. Without it, your emails display a 'via klaviyo.com' notice and DMARC won't align. Here's the complete setup.
1SPF Record Setup
Recommended SPF record for Klaviyo:
v=spf1 include:spf.klaviyo.com ~allKlaviyo uses a subdomain-based authentication model. You add CNAMEs for a dedicated sending subdomain (e.g., email.yourdomain.com) rather than modifying your root domain's SPF directly. The SPF include is automatically handled by the subdomain setup.
Step-by-step setup:
- 1In Klaviyo, go to Account Settings → Email → Dedicated Sending Domain
- 2Choose a subdomain (e.g., email.yourdomain.com or klaviyo.yourdomain.com)
- 3Klaviyo provides 4–5 CNAME records to add to your DNS
- 4Add all CNAME records to your DNS provider under the subdomain
- 5Return to Klaviyo and click Verify DNS Records
- 6Once verified, set this as your sending domain in Klaviyo
2DKIM Setup
Example DKIM record location:
kl._domainkey.email.yourdomain.comKlaviyo's DKIM is set up via CNAME delegation on your sending subdomain. The DKIM selector signs emails with your subdomain (e.g., email.yourdomain.com) — not your root domain. Your DMARC record must use sp= or cover subdomain alignment.
Step-by-step setup:
- 1Complete the dedicated sending domain setup (includes DKIM CNAMEs)
- 2Klaviyo provides specific CNAME records for DKIM authentication
- 3Verify the CNAME records are correctly propagated
- 4In Klaviyo, confirm Domain Authentication shows 'Verified'
- 5Test with our DKIM checker using your subdomain
3DMARC Policy
Recommended DMARC record:
v=DMARC1; p=quarantine; rua=mailto:dmarc@yourdomain.com; sp=quarantine; pct=100Add as a TXT record at: _dmarc.yourdomain.com
Since Klaviyo sends from a subdomain of your domain, your root DMARC record should include sp=quarantine (or sp=reject) to cover subdomains. Without sp=, your subdomains may be unprotected.
Common Klaviyo Deliverability Issues
Klaviyo emails showing 'via klaviyo.com' in Gmail
Complete the dedicated sending domain setup. This requires adding CNAME records and verifying them in Klaviyo. Once verified and set as your sending domain, the 'via' notice disappears.
High unsubscribe rates hurting Klaviyo sender score
Review your segmentation strategy. Klaviyo's predictive analytics can identify likely-to-unsubscribe profiles. Sunset flows can automatically suppress disengaged subscribers. Check your domain isn't blacklisted.
DMARC failing for Klaviyo emails
The DKIM d= tag should match your sending subdomain. Check alignment mode — if your DMARC uses adkim=s (strict), the DKIM domain must exactly match your From: domain including subdomain.
Is Your Klaviyo Domain Blacklisted?
Authentication passing is necessary — but not sufficient. Check if your sending domain or IP is on any of 60 blacklists. Free, instant, no signup.
Check Your Domain FreeChecks all 60 blacklists + SPF, DKIM, DMARC, MX in under 10 seconds