Setup Guides · Klaviyo
Klaviyo Dedicated Sending Domain: Deliverability & DMARC
Klaviyo calls it a branded sending domain - a subdomain of your own domain (their example is send.example.com) that Klaviyo signs with your DKIM instead of the shared klaviyomail.com. It drops the "via klaviyomail.com" line, gives you your own sender reputation, and - the part that matters for 2026 - aligns SPF and DKIM to your domain so your mail passes DMARC. This guide is the exact records (NS delegation or CNAMEs), what Klaviyo handles for you, the DMARC record you still publish yourself, and the failures we keep finding in audits.
Last updated 11 September 2026 · applies to Klaviyo branded (dedicated) sending domains
What Klaviyo authenticates for you (and what it does not)
- DKIM - Klaviyo does this for you. Once your branded domain is set up, mail is DKIM-signed by your own domain (selectors
km1/km2for marketing) in addition to a shared Klaviyo signature. You publish the records that point at Klaviyo's hosted keys; Klaviyo generates and rotates the keys. - SPF and the return-path - handled automatically. On the shared sending domain your bounces run through Klaviyo's own
klaviyomail.comreturn-path, so SPF passes but does not align to you. Once your branded domain is active the return-path moves onto that subdomain (Klaviyo's own mail usesbounces…@send.klaviyo.com), and Klaviyo publishes the SPF record for it inside the zone you delegated or CNAMEd - which is why SPF then aligns. Either way Klaviyo's docs say you do not add your own SPF and DKIM records. - DMARC - mostly yours. Klaviyo can generate a starter DMARC record (
p=none, monitoring-only) with its Add DMARC record option during setup, and for Entri-eligible domains it can publish that record to your DNS for you. But it won't run an enforcement policy (p=quarantine/p=reject), tune yourruareports, or manage your ongoing DMARC posture - that stays with you at_dmarc.yourdomain.com.
The upshot: an active branded sending domain gives you aligned SPF and aligned DKIM (because the return-path and signature both sit under your organizational domain), which is exactly what a DMARC pass needs - but the DMARC policy itself is a record only you can publish.
What you need
- A Klaviyo account with access to Settings → Domains (or the sending-domain setup flow).
- Access to your domain's public DNS - and, if you use Cloudflare, the ability to set the CNAME records to DNS only (grey cloud).
- A friendly-From address on your own domain (not
@gmail.comor@yahoo.com) whose root matches the branded sending domain.
The setup, step by step
1 Start the branded sending domain and choose a subdomain
In Klaviyo go to Settings → Domains → Add a sending domain and enter the subdomain you want to send from. Klaviyo's own example is send.example.com; a subdomain (send, email, updates) is required - do not use your root domain. The subdomain's root must match the domain in your friendly-From address so that DMARC aligns.
2 Pick a routing method: Dynamic (NS) or Static (CNAME)
Klaviyo offers two ways to publish the records. Dynamic routing is Klaviyo's recommended option.
Dynamic routing (NS delegation). You delegate the sending subdomain to Klaviyo's nameservers, and Klaviyo manages the DKIM, SPF and return-path records inside that delegated zone - so you never touch the individual keys again:
Type Host Value NS send.yourdomain.com [ns1 value from your Klaviyo account] NS send.yourdomain.com [ns2 value from your Klaviyo account] NS send.yourdomain.com [ns3 value from your Klaviyo account] NS send.yourdomain.com [ns4 value from your Klaviyo account] TXT yourdomain.com klaviyo-site-verification=[your public API key]
Static routing (CNAME). If your DNS provider can't delegate a subdomain, publish CNAMEs instead - one for the sending subdomain and one per DKIM selector:
Type Host Value CNAME send.yourdomain.com [account].klaviyodns.com CNAME km1._domainkey.yourdomain.com km1.domainkey.[account].klaviyodns.com CNAME km2._domainkey.yourdomain.com km2.domainkey.[account].klaviyodns.com TXT yourdomain.com klaviyo-site-verification=[your public API key]
The target values are unique to your account
Klaviyo is explicit: "these are just examples and the actual CNAME record values for your account will be different - make sure to use the values generated in your account." The DKIM selectors are stable (km1/km2 for marketing sends, kt1/kt2 for transactional, ks1/ks2 for service; a second domain of the same type increments to km3/km4), but the *.klaviyodns.com targets and NS hostnames are generated per account - copy them from your own screen, never from a guide.
3 If you use Cloudflare, set the CNAMEs to DNS only
Publish the records at your DNS host. On Cloudflare, each Klaviyo CNAME must be DNS only (grey cloud), not proxied - only A, AAAA and CNAME records have a proxy toggle, so the NS and TXT records can't be proxied in the first place. This is Klaviyo's single most-documented failure: proxying hides the record behind the CDN and Klaviyo can't verify it, and it "will need to stay disabled after the setup process as well for emails to authenticate as expected." Watch for a provider that auto-appends your domain to a CNAME target (...klaviyodns.com.yourdomain.com); add a trailing dot or use the full value exactly as shown.
4 Verify, then activate
Back in Klaviyo, click Verify. The status resolves to Verification success, Verification error, or a conflict notice. DNS can take up to 48 hours to propagate worldwide, so a fresh "error" often just means you checked too early. Once it verifies, click Activate to start sending on the branded domain - from then on your mail drops the "via klaviyomail.com" line, carries your own DKIM signature, and the return-path moves onto your sending subdomain.
5 Publish a DMARC record
Klaviyo can generate a starter p=none record for you (the Add DMARC record toggle during setup) and publish it automatically if your DNS provider is Entri-eligible. If you're adding it yourself, create a TXT record at _dmarc.yourdomain.com in monitoring mode:
Type Host Value TXT _dmarc.yourdomain.com v=DMARC1; p=none; rua=mailto:[email protected]
Either way, the enforcement work stays with you: collect the aggregate reports, confirm your Klaviyo mail (and every other sender - your mailbox provider, your helpdesk, your billing system) passes aligned, then move the policy through p=quarantine to p=reject. If your domain already has a DMARC record, keep it - don't let a fresh p=none overwrite an enforced policy. Our DMARC enforcement guide walks that path, and the Postbox DMARC Monitor reads the reports for you.
How SPF, DKIM and DMARC line up here
- DKIM - Klaviyo signs with your domain using the
km1/km2selectors (published atkm1._domainkey.yourdomain.comin Static routing, or inside the delegatedsend.zone in Dynamic routing), which shares your organizational domain with the visible From, so DKIM aligns (relaxed alignment, DMARC's default). - SPF - once the branded domain is active the return-path sits on your sending subdomain, and because that subdomain shares your organizational domain with the visible From, SPF aligns under relaxed alignment. You don't manage the record; Klaviyo publishes it in the delegated or CNAMEd zone. (On the shared sending domain the return-path stays on
klaviyomail.com, so SPF passes but does not align - which is why a branded domain matters.) - DMARC - passes when either SPF or DKIM aligns; an active branded domain gives you both. See our SPF, DKIM and DMARC guide for how the three fit together. Keep DMARC alignment relaxed (the default) - setting
adkim=s/aspf=scan break alignment when the sending subdomain and the From domain are related but not identical.
Gmail and Yahoo bulk-sender rules (why this is not optional)
Since 1 February 2024, Gmail enforces sender requirements on anyone sending 5,000+ messages a day to Gmail (all your Gmail traffic counts toward that threshold, transactional included); Yahoo applies comparable requirements without publishing a numeric threshold. Klaviyo's own guidance for meeting them: (1) set up a branded sending domain with DMARC configured, (2) align your From address with that branded domain, and (3) make unsubscribing easy (one-click list-unsubscribe). Sending marketing mail from an @gmail.com or @yahoo.com From address no longer works - use a domain you own. Klaviyo is blunt about it: a bulk sender by the inbox providers' standards must set up a branded sending domain - it's a requirement now, not a nice-to-have. This guide's steps 1-5 satisfy requirements 1 and 2; Klaviyo adds the one-click unsubscribe header for you.
Dedicated vs shared IP
By default Klaviyo sends from a shared IP pool that stays warm across many accounts - the right choice for small or irregular senders, nothing to configure. A dedicated IP isolates your reputation but is only worth it at high, consistent volume; it isn't a self-serve toggle - you arrange it through your Klaviyo Customer Success Manager. A new dedicated IP must be warmed, and Klaviyo runs an automated ~30-40 day warm-up on a non-linear curve (most of the ramp is near the end); favour campaigns over flows and consistency over spikes during that window. The branded sending domain - not the IP - is what Gmail and Yahoo require.
The failures we keep finding
A CNAME left proxied on Cloudflare (orange cloud)
The failure Klaviyo documents most often. A proxied CNAME can't be verified, and even after verification an orange-clouded record stops the mail authenticating. Set every Klaviyo CNAME to DNS only and leave it that way permanently. (NS and TXT records have no proxy toggle, so they're not the culprit.)
Adding a second SPF record
If your root domain already publishes an SPF TXT for other senders, do not add another - a hostname may have only one SPF record, and two produce a permerror. Klaviyo's SPF is added through the records you publish on the sending subdomain; your root SPF is separate and should stay a single record.
Using account-specific values from a guide
The *.klaviyodns.com targets and NS hostnames are generated per account. Copy them from your Klaviyo setup screen - values lifted from a blog or another account will never verify.
Verifying before DNS has propagated
DNS can take up to 48 hours. A "Verification error" moments after you publish usually means the record hasn't propagated, not that it's wrong - re-check with a DNS lookup and wait.
Expecting Klaviyo to run DMARC for you
Klaviyo can generate a starter p=none record and auto-publish it via Entri, but it stops there - it won't take you to enforcement or manage your reports. A branded domain left with only p=none (or no _dmarc at all) isn't protecting you; drive the policy to p=quarantine/p=reject yourself once your senders align.
Leaving click-tracking links unbranded
The sending domain handles authentication, but click-through links still show Klaviyo's default tracking domain until you add a dedicated click-tracking domain (a separate CNAME). Brand it so links match your domain - better for trust and for consistent link reputation.
Verify it end to end
Klaviyo showing the domain as verified and active means the records exist - it doesn't prove a real send authenticates. Confirm on an actual message:
- Send a Klaviyo campaign or flow to a seed address, then run it through Postbox Mailtester and confirm DKIM pass with
d=your domain, SPF aligned, and DMARC pass (aligned). - Or read the received message's
Authentication-Resultsheader:dkim=pass header.d=yourdomain.comanddmarc=pass. If the From line still shows "via klaviyomail.com", the branded domain isn't active yet - go back to step 4.
Frequently asked questions
What is a Klaviyo branded (dedicated) sending domain?
A subdomain of your own domain (Klaviyo's example is send.example.com) that Klaviyo signs with your DKIM instead of the shared klaviyomail.com. It removes the "via klaviyomail.com" line, gives you your own sender reputation, and aligns SPF and DKIM to your domain so your mail passes DMARC. "Branded sending domain" is Klaviyo's own term; "dedicated sending domain" means the same thing.
What DNS records does a Klaviyo branded sending domain need?
Either NS records delegating send.yourdomain.com to Klaviyo (Dynamic routing, recommended - Klaviyo then manages DKIM/SPF/return-path in that zone), or CNAME records (Static routing) - a sending-subdomain CNAME plus km1._domainkey and km2._domainkey CNAMEs. Both also use a klaviyo-site-verification TXT on your root. Target values are per-account - use the ones your screen shows.
Do I need to add SPF and a bounce record for Klaviyo?
No. Klaviyo handles the return-path on klaviyomail.com (shared) or on your branded subdomain (once active) automatically and adds the required SPF through the records you publish; its docs say you don't add your own SPF/DKIM. Just don't create a second SPF TXT on your root if one already exists - merge, don't duplicate.
Does Klaviyo set up DMARC for me?
Partly. Klaviyo can generate a starter p=none record during branded-domain setup (the Add DMARC record toggle) and auto-publish it for Entri-eligible domains, but it won't run your enforcement policy or read your reports - moving to p=quarantine/p=reject stays with you at _dmarc.yourdomain.com. Once a branded domain is active it shares your root and Klaviyo signs with your DKIM, so SPF and DKIM align and your Klaviyo mail passes once the policy is live.
Why does my Klaviyo domain fail to verify on Cloudflare?
Usually because a CNAME is proxied (orange cloud) - Klaviyo can't see a record hidden behind the CDN, and the proxy must stay off after setup or the mail won't authenticate. Set every Klaviyo CNAME to DNS only; only A, AAAA and CNAME records have a proxy toggle, so the NS and TXT records can't be proxied anyway. The other cause is checking before DNS propagates (up to 48 hours).
Do I need a dedicated IP with Klaviyo?
Most senders don't. Shared IPs (warm by default) suit small or irregular volume. A dedicated IP is for high, consistent volume, arranged via your Customer Success Manager, and must be warmed (~30-40 days automated). The branded domain, not the IP, is what Gmail and Yahoo require.
Sources (Klaviyo Help Center): Set up a branded sending domain · Understanding email authentication · Troubleshooting branded sending domain issues · DNS and SPF setup troubleshooting · Verify email authentication configurations · Dedicated vs shared IPs · Gmail & Yahoo sender requirements.
Not sure your Klaviyo mail is actually aligned?