Understanding Klaviyo Email Authentication
Klaviyo requires a Dedicated Sending Domain with 4 CNAME records to authenticate SPF and DKIM under your brand.
When Klaviyo delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Klaviyo's IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.
Required DNS Records for Klaviyo
Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):
| Type | Host / Name | Value / Target | TTL | Purpose |
|---|---|---|---|---|
| CNAME | kl._domainkey | kl.domainkey.klaviyomail.com | 3600 | Klaviyo DKIM 1. |
Step-by-Step Setup Instructions
In Klaviyo > Settings > Email > Dedicated Sending Domain > Add domain.
Add the 4 CNAME records to your DNS.
Click Verify Domain in Klaviyo.
Common Klaviyo SPF Configuration Mistakes
× Shared Domain Warning
Cause: Using klaviyomail.com headers.
Fix: Set up dedicated domain.
Frequently Asked Questions
Does Klaviyo require a dedicated sending domain?
Yes, for bulk senders delivering over 5,000 emails/day.
What 4 CNAME records does Klaviyo require for domain authentication?
Klaviyo generates 4 CNAME records: kl._domainkey and kl2._domainkey (DKIM keys), return.[yourdomain].com (Return-Path CNAME for SPF alignment), and tracking.[yourdomain].com (click/open tracking subdomain). All 4 must be published and verified.
What is the Klaviyo SPF include string?
Klaviyo uses include:klaviyo.com as the SPF mechanism. However, if you are using the dedicated sending domain feature, SPF alignment is handled through the CNAME-based Return-Path, and you may not need to manually add include:klaviyo.com to your root record.
Why does Klaviyo use CNAME-based DKIM instead of TXT?
Klaviyo uses CNAME-based DKIM (kl._domainkey and kl2._domainkey) to support automated background key rotation without requiring you to update DNS records when Klaviyo cycles cryptographic keys.
What happens to my Klaviyo deliverability if I do not set up a dedicated sending domain?
Without a dedicated sending domain, Klaviyo sends from a shared subdomain (e.g. @klaviyomail.com or @email.yourdomain.klaviyomail.com). Your From: address may display "via klaviyomail.com" in some clients, and SPF/DKIM do not align with your custom domain, making DMARC enforcement impossible on your domain.
How does Klaviyo impact the DNS 10-lookup limit?
include:klaviyo.com resolves to a single additional DNS lookup. If your SPF record already includes many providers, check the total count using IncogSay's SPF Checker. RFC 7208 sets a hard limit of 10 DNS lookups; exceeding it causes a PermError that fails all SPF authentication.