Insights · email authentication

How to set up DMARC for Klaviyo, and what SPF and DKIM do first

Three DNS records, one order to publish them in, and the mistake that stops a Shopify brand's sends reaching anybody at all.

The Google app icon on a phone home screen, Calendar above it and Twitter beside it, on a dark red wallpaper
Theo Tziapouras, founder and strategy at Engage Commerce
Theo TziapourasFounder and strategy
11 August 2026 1,268 words6 minute read
In short · six parts

Most brands find out their authentication is wrong on the morning of a big send, when there's no calm way to fix it. Done properly it's one afternoon in DNS. Then it holds for years.

Three Rebel Aromas eau de parfume bottles standing in a row against a plaster wall

Each record answers a different question about you

SPF says which servers are allowed to send for your domain. DKIM signs the message, so a receiver can prove nobody altered it on the way. DMARC says what should happen when one of those checks fails, and asks for a report when it does.

RecordWhat it provesWhere it lives
SPFThat Klaviyo is allowed to send for your domainA TXT record on the sending domain
DKIMThat the message left Klaviyo intact and signed by youCNAME records Klaviyo generates for you
DMARCWhat a receiver should do when SPF or DKIM fails, and where to send the reportsA TXT record on the _dmarc subdomain

None of this lives inside Klaviyo, and none of it is optional any more. Put those two facts together and you've got the reason authentication takes three weeks in most companies.

The bulk sender rules turned good practice into a gate

Google and Yahoo both publish requirements for anyone sending in bulk, and authentication is the first of them. Google sets its out in the email sender guidelines. An unauthenticated bulk sender is treated as suspicious by default.

Shopify brands get caught more often than most. The shop, the helpdesk, the review tool and the marketing platform all want to send as the same domain, and each one is its own authentication job. The one nobody remembers is the one that fails.

There's a second reason to do it, and it has nothing to do with getting delivered. A domain with no DMARC record is a domain anybody can send as, and the people who do that are sending fake order confirmations to your customers.

Publish them in this order or you will block your own mail

  1. Choose a sending subdomain of the shop, not the shop domain itself or a free mailbox
  2. Add that domain in Klaviyo and publish the DKIM and SPF records it hands you
  3. Send a real campaign to yourself and confirm both checks pass in the message headers
  4. Only then publish DMARC, on a monitoring policy, so nothing of yours gets thrown away while you watch
  5. Read a fortnight of reports and find every other system sending as you, then authenticate it or stop it
  6. Tighten the policy to quarantine, and later to reject, once the reports are boring

The order matters because DMARC is an instruction to throw your own mail away when the other two fail. Publish a strict policy on day one and you're enforcing a rule you've never tested. Start in monitoring, read what comes back, then tighten.

Klaviyo generates the records, your domain host publishes them

Klaviyo hands you the values in a few minutes. Getting them into DNS is a different conversation, usually with whoever set the domain up years ago and has since left the company.

Book that person's time before you start, not after. Every slow authentication project we've taken over was slow for this reason. Never for a technical one.

And be careful with anybody who offers to take the domain off your hands entirely. Your DNS is the one asset in this you should never hand over, because whoever controls it controls whether your customers hear from you at all. We send the values over and ask for them to be published. We don't want the login.

How to check it passes, without trusting a preview tool

Send a real campaign from Klaviyo to an address you can open in Gmail, then read the message headers. You want a pass beside all three on a live send, not on a checker's own test message.

A Samsung tablet lying on a desk with the Google search page open in a browser, the edge of a laptop beside it
  • The from address is on the domain you authenticated, not a lookalike
  • SPF passes on the return path Klaviyo actually uses
  • DKIM shows your own signing domain, not the platform's
  • DMARC is aligned, meaning the domain that passed is the domain the reader sees
  • A public DNS lookup shows one SPF record, not three left over from old platforms

Alignment is the part people miss. SPF and DKIM can both pass on a message that DMARC still fails, because the domain that passed isn't the domain in the from line.

The four ways this breaks on a Shopify store

  • Two SPF records on one domain, which is invalid, so both are ignored
  • A reject policy published before anybody read the reports, with the helpdesk still unauthenticated
  • Order confirmations on one domain and marketing on another, with only one of them set up
  • A free mailbox in the from address, which the bulk sender rules will not accept

Three of those four are somebody being helpful in a hurry. Nobody breaks authentication on purpose, which is exactly why nobody notices until a campaign disappears.

If that's beyond the people you've got, it's the first thing we do on a new account, before a single flow gets rebuilt. What we do inside Klaviyo covers the rest, and the way we build an email system shows where it sits in the order of work.

Theo Tziapouras, founder and strategy at Engage Commerce

Theo Tziapouras

Founder and strategy at Engage Commerce, the ecommerce agency for 7 and 8 figure DTC brands.

Does Klaviyo set up SPF and DKIM for me?

Klaviyo generates the records and verifies them once they're live, but it can't publish them for you. They go into DNS wherever the domain is managed, which might be Shopify, your registrar or an old agency account. Finding out who holds that login is the step that stalls, so do it first.

Do I need DMARC if SPF and DKIM already pass?

Yes, if you send in bulk. Google and Yahoo both ask bulk senders for a DMARC record, and without one you've no way of seeing who else is sending as your brand. Start on a monitoring policy and leave it there until the reports stop showing you anything new.

What is a sending subdomain, and do I need one?

It's a subdomain used only for marketing mail, such as news.yourshop.com. It keeps campaign reputation away from the order confirmations and password resets that have to arrive whatever else happens. Most Shopify brands should use one, and Klaviyo walks you through creating it.

Will a strict DMARC policy stop my order confirmations?

It will if they're sent from a system you haven't authenticated, which is the usual reason people are frightened of it. That's what the monitoring stage is for: the reports name every service sending as you, including the ones nobody told you about. Fix them all, then tighten the policy.

How soon after fixing this do things improve?

The technical part takes effect on the next send. Reputation is slower, because mailbox providers want a few weeks of clean sending before they revise their opinion of you. Fix the records, keep the sending pattern steady, and don't judge it on one campaign.

Not got your answer?Chat to us
End matter

Authentication is the cheapest insurance in email

Nobody has ever thanked us for a DMARC record. It's invisible when it works and expensive when it's missing, which is a rotten combination for something that takes an afternoon. Do it before peak season instead of during it, do it once, and write down every system that sends as you. The next person shouldn't have to guess.

Theo TziapourasFounder and strategy · Engage Commerce

Would you rather this was just handled?

Bring your Klaviyo account and the thing annoying you most. We will tell you what we would fix first, on the call, before you spend anything.

Engage CommerceTheo Tziapouras, founder of Engage Commerce

Book a call with our founder.

We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊