What is DKIM, and whose name is your email signed in?
A signature on every email that the receiving server checks against a key published in DNS. Whose name is on that signature is the part most shops never look at.
- 026DKIM (DomainKeys Identified Mail)
- An email authentication method that allows the receiver to verify that an email was sent and authorised by the owner of the domain. DKIM helps ensure email security and improves deliverability by verifying the legitimacy of your emails.

- Lives in
- Your DNS, as records Klaviyo generates for you to publish
- Proves
- Which domain signed the email, and that nobody changed it on the way
- Doesn't prove
- That the email is wanted, or that the sender is honest
- Check it with
- Show original in Gmail, on a real send
A tamper seal the receiving server can check
Think of it as a wax seal. Your sending platform signs each email with a private key. The matching public key sits in the signing domain's DNS, where any receiving server can look it up and check the seal.
If the seal holds, the receiver knows two things: which domain signed the email, and that nothing in the signed parts changed in transit. That's it. Spammers sign their mail too. A pass proves who you are, not that anyone wants to hear from you.
Signed by your shop, or signed by Klaviyo
Here's the bit that catches people. Out of the box, Klaviyo signs your email with a domain of its own, so DKIM passes from day one. It just passes for Klaviyo.
That matters the moment you publish DMARC, which wants the signing domain to match the domain in your from address. The fix is a branded sending domain, a subdomain such as send.yourshop.com, so your mail gets signed in your own name. Klaviyo's help centre walks through the set-up.
| Who sends as you | Whose signature | Counts for your DMARC |
|---|---|---|
| Klaviyo, before any set-up | Klaviyo's | No |
| Klaviyo, with a branded sending domain | Yours | Yes |
| Shopify, the helpdesk, the review app | Whatever each was set up with | Only if someone authenticated it |
How to read the DKIM result on a real email
- Send a real campaign from Klaviyo to a Gmail address you can open
- Open it and choose Show original from the three-dot menu
- Find the DKIM line and check it says PASS
- Check the domain beside it is yours, not your platform's
- Repeat with an order confirmation and a helpdesk reply
That last step is where the surprises live. Every tool that sends as your shop needs its own signature, and the forgotten one is usually the helpdesk or the review app. Google's sender guidelines expect bulk senders to have DKIM, SPF and DMARC all in place.
Related terms
FAQs

Why does DKIM pass but DMARC still fail?
Because the domain that signed the email isn't the domain in your from address. Klaviyo's default signature passes, but for Klaviyo's own domain, so DMARC has nothing of yours to match. Set up a branded sending domain and the signature carries your shop's name, which is what DMARC is looking for.
Does DKIM stop people sending fake emails as my shop?
Not on its own. A fraudster simply doesn't sign with your key, and without a DMARC policy nothing tells the receiving server that unsigned mail claiming to be you should be refused. DKIM is the evidence. A DMARC policy of quarantine or reject is the instruction to act on it.
Is DKIM enough without SPF?
For a shop sending at volume, no. Google asks bulk senders for SPF, DKIM and DMARC together. The two also fail differently. SPF checks the server that handed the email over, so forwarding often breaks it, while a DKIM signature travels with the message. You want both passing.
Rather we explained it on your own account?
Bring your Klaviyo account to a growth consultation. We'll walk through what this means for your numbers, in plain English, and what we'd fix first.


Half an hour with Theo, our founder.
We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊



