Klaviyo SPF, DKIM and DMARC
Delegate a sending subdomain to Klaviyo — by NS or by CNAME — and let it publish SPF and DKIM for you.
Klaviyo calls this a branded sending domain, and it is a delegation rather than a list of records you maintain. You hand Klaviyo a subdomain — `send.yourdomain.com`, or whatever you choose — and Klaviyo publishes the SPF and DKIM values behind it. Klaviyo states that "the necessary SPF record is automatically added through the CNAME or NS records added during setup".
There are two routing modes and they produce completely different record sets. **Dynamic** routing is four NS records that delegate the whole subdomain to Klaviyo, and it is what Klaviyo recommends. **Static** routing is CNAMEs instead, for DNS hosts that cannot create NS records on a subdomain. Either way you also add one TXT record on your root domain to prove you own it.
The reason this matters for DMARC is alignment, not SPF. Because the sending subdomain is yours, the DKIM signature is on your domain and matches the root domain of your friendly-from address, so DMARC passes through DKIM.
The records Klaviyo needs
NS · host send
ns1.klaviyo.com ns2.klaviyo.com ns3.klaviyo.com ns4.klaviyo.com
Dynamic routing (recommended): four NS records on the same name, delegating that subdomain to Klaviyo. Use the subdomain Klaviyo shows you — `send` is only an example. Nothing else of yours can live under a delegated name.
TXT · host @
klaviyo-site-verification=<your public API key>
Ownership check, on the root domain, in both routing modes. This is not an SPF record and does not belong in one.
CNAME · host send
<n>.klaviyodns.com
Static routing only, as an alternative to the four NS records above. The leading number is account-specific — copy it from the Klaviyo setup screen.
CNAME · host km1._domainkey
km1.domainkey.<n>.klaviyodns.com
Static routing only. First DKIM selector for a **marketing** domain. Klaviyo rotates the key behind the name.
CNAME · host km2._domainkey
km2.domainkey.<n>.klaviyodns.com
Static routing only. Second marketing selector; both are required, for the same rotation reason as Microsoft 365 and SendGrid.
Values shown with placeholders are account-specific — copy the exact value from Klaviyo, never from a guide.
What goes wrong
- The selector prefix depends on the send type
- Marketing domains use `km1` and `km2`, transactional domains use `kt1` and `kt2`, and service domains use `ks1` and `ks2`. Probing `klaviyo._domainkey` or Mailchimp-style `k1._domainkey` finds nothing. If you later add a transactional domain, it brings its own `kt` pair — it does not reuse the `km` records.
- There is no Klaviyo SPF include to add
- Klaviyo publishes SPF behind the delegated subdomain, so editing your root SPF record does nothing for campaign mail. An include copied from an older guide is not helping, and it is spending one of your 10 SPF lookups alongside Google Workspace or Microsoft 365.
- Dynamic routing takes the whole subdomain
- Four NS records delegate that name to Klaviyo entirely. Any record you already have at `send.yourdomain.com` stops resolving, and you cannot add one later from your own DNS panel. Pick a subdomain you are not using for anything else, or choose static routing.
- The friendly-from has to be on the same root domain
- Klaviyo's DMARC guidance is that the branded sending domain must match the root domain in your friendly-from address. Sending as `hello@othercompany.com` from a domain branded as `yourdomain.com` leaves DKIM aligned to the wrong domain and DMARC fails.
- Proxied or flattened records break the delegation
- If your DNS host proxies CNAMEs or rewrites NS records at a subdomain, Klaviyo cannot serve the keys. On Cloudflare these records must be DNS-only.
Questions
- What is the Klaviyo SPF record?
- There is not one to add. Klaviyo publishes SPF behind the sending subdomain you delegate during branded sending domain setup, so no `include:` goes on your root domain. You still need SPF for whatever sends your ordinary business mail.
- What are the Klaviyo DKIM selectors?
- With static routing, `km1._domainkey` and `km2._domainkey` for a marketing domain, pointing at `km<n>.domainkey.<n>.klaviyodns.com`. Transactional domains use `kt1`/`kt2`, service domains `ks1`/`ks2`. With dynamic routing the keys live inside the delegated subdomain and you publish no DKIM record yourself.
- Should I use dynamic or static routing in Klaviyo?
- Klaviyo recommends dynamic (the four NS records) for sending performance. Use static CNAMEs when your DNS host cannot create NS records on a subdomain, or when you need to keep other records under that name.
- Why are my Klaviyo emails going to spam?
- Check authentication first: that the delegation resolves, that the selectors for your send type are reachable, and that DMARC aligns with your friendly-from domain. If all of that is clean, what is left is list quality, complaint rate and content — which no DNS change fixes.
- Do I need DMARC for Klaviyo?
- Yes. Gmail and Yahoo require bulk senders to publish DMARC, and a branded sending domain is what lets your Klaviyo mail pass it. Start at `p=none` with a `rua` address, then raise the policy once reports are clean.
Fix this from ChatGPT or Claude
MailVakt is an MCP server, so your assistant can run this check itself, read the findings and walk you through the DNS edit. Ask it:
“example.com sends campaigns through Klaviyo. Check the km1 and km2 DKIM selectors, confirm DMARC will align, and tell me what is missing.”
- Claude: Settings → Connectors → Add custom connector, then paste
https://mcp.mailvakt.com/mcp. - Cursor and other MCP clients: add the same address as an MCP server. Setup details.
Checks are free and need no account. Sign in only to collect DMARC reports for a domain.