Official DNS Guide • E-commerce Marketing & SMS

Klaviyo SPF Record Setup & Validator

Set up Klaviyo dedicated sending domain, configure CNAME records for DKIM (kl/kl2._domainkey), and establish custom Return-Path.

Quick Answer • Exact Klaviyo SPF Syntax

To authorize Klaviyo to send emails on behalf of your domain, add include:klaviyo.com to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:klaviyo.com ~all.

Live Klaviyo DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Klaviyo Email Authentication

Klaviyo requires a Dedicated Sending Domain with 4 CNAME records to authenticate SPF and DKIM under your brand.

When Klaviyo delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Klaviyo's IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Klaviyo

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
CNAMEkl._domainkeykl.domainkey.klaviyomail.com3600Klaviyo DKIM 1.

Step-by-Step Setup Instructions

1

In Klaviyo > Settings > Email > Dedicated Sending Domain > Add domain.

2

Add the 4 CNAME records to your DNS.

3

Click Verify Domain in Klaviyo.

Common Klaviyo SPF Configuration Mistakes

× Shared Domain Warning

Cause: Using klaviyomail.com headers.

Fix: Set up dedicated domain.

Frequently Asked Questions

Does Klaviyo require a dedicated sending domain?

Yes, for bulk senders delivering over 5,000 emails/day.

What 4 CNAME records does Klaviyo require for domain authentication?

Klaviyo generates 4 CNAME records: kl._domainkey and kl2._domainkey (DKIM keys), return.[yourdomain].com (Return-Path CNAME for SPF alignment), and tracking.[yourdomain].com (click/open tracking subdomain). All 4 must be published and verified.

What is the Klaviyo SPF include string?

Klaviyo uses include:klaviyo.com as the SPF mechanism. However, if you are using the dedicated sending domain feature, SPF alignment is handled through the CNAME-based Return-Path, and you may not need to manually add include:klaviyo.com to your root record.

Why does Klaviyo use CNAME-based DKIM instead of TXT?

Klaviyo uses CNAME-based DKIM (kl._domainkey and kl2._domainkey) to support automated background key rotation without requiring you to update DNS records when Klaviyo cycles cryptographic keys.

What happens to my Klaviyo deliverability if I do not set up a dedicated sending domain?

Without a dedicated sending domain, Klaviyo sends from a shared subdomain (e.g. @klaviyomail.com or @email.yourdomain.klaviyomail.com). Your From: address may display "via klaviyomail.com" in some clients, and SPF/DKIM do not align with your custom domain, making DMARC enforcement impossible on your domain.

How does Klaviyo impact the DNS 10-lookup limit?

include:klaviyo.com resolves to a single additional DNS lookup. If your SPF record already includes many providers, check the total count using IncogSay's SPF Checker. RFC 7208 sets a hard limit of 10 DNS lookups; exceeding it causes a PermError that fails all SPF authentication.