How to set up DMARC for Klaviyo, and what SPF and DKIM do first
Three DNS records, one order to publish them in, and the mistake that stops a Shopify brand's sends reaching anybody at all.
Most brands find out their authentication is wrong on the morning of a big send, when there's no calm way to fix it. Done properly it's one afternoon in DNS. Then it holds for years.

Each record answers a different question about you
SPF says which servers are allowed to send for your domain. DKIM signs the message, so a receiver can prove nobody altered it on the way. DMARC says what should happen when one of those checks fails, and asks for a report when it does.
| Record | What it proves | Where it lives |
|---|---|---|
| SPF | That Klaviyo is allowed to send for your domain | A TXT record on the sending domain |
| DKIM | That the message left Klaviyo intact and signed by you | CNAME records Klaviyo generates for you |
| DMARC | What a receiver should do when SPF or DKIM fails, and where to send the reports | A TXT record on the _dmarc subdomain |
None of this lives inside Klaviyo, and none of it is optional any more. Put those two facts together and you've got the reason authentication takes three weeks in most companies.
The bulk sender rules turned good practice into a gate
Google and Yahoo both publish requirements for anyone sending in bulk, and authentication is the first of them. Google sets its out in the email sender guidelines. An unauthenticated bulk sender is treated as suspicious by default.
Shopify brands get caught more often than most. The shop, the helpdesk, the review tool and the marketing platform all want to send as the same domain, and each one is its own authentication job. The one nobody remembers is the one that fails.
There's a second reason to do it, and it has nothing to do with getting delivered. A domain with no DMARC record is a domain anybody can send as, and the people who do that are sending fake order confirmations to your customers.
Publish them in this order or you will block your own mail
- Choose a sending subdomain of the shop, not the shop domain itself or a free mailbox
- Add that domain in Klaviyo and publish the DKIM and SPF records it hands you
- Send a real campaign to yourself and confirm both checks pass in the message headers
- Only then publish DMARC, on a monitoring policy, so nothing of yours gets thrown away while you watch
- Read a fortnight of reports and find every other system sending as you, then authenticate it or stop it
- Tighten the policy to quarantine, and later to reject, once the reports are boring
The order matters because DMARC is an instruction to throw your own mail away when the other two fail. Publish a strict policy on day one and you're enforcing a rule you've never tested. Start in monitoring, read what comes back, then tighten.
Klaviyo generates the records, your domain host publishes them
Klaviyo hands you the values in a few minutes. Getting them into DNS is a different conversation, usually with whoever set the domain up years ago and has since left the company.
Book that person's time before you start, not after. Every slow authentication project we've taken over was slow for this reason. Never for a technical one.
And be careful with anybody who offers to take the domain off your hands entirely. Your DNS is the one asset in this you should never hand over, because whoever controls it controls whether your customers hear from you at all. We send the values over and ask for them to be published. We don't want the login.
How to check it passes, without trusting a preview tool
Send a real campaign from Klaviyo to an address you can open in Gmail, then read the message headers. You want a pass beside all three on a live send, not on a checker's own test message.

- The from address is on the domain you authenticated, not a lookalike
- SPF passes on the return path Klaviyo actually uses
- DKIM shows your own signing domain, not the platform's
- DMARC is aligned, meaning the domain that passed is the domain the reader sees
- A public DNS lookup shows one SPF record, not three left over from old platforms
Alignment is the part people miss. SPF and DKIM can both pass on a message that DMARC still fails, because the domain that passed isn't the domain in the from line.
The four ways this breaks on a Shopify store
- Two SPF records on one domain, which is invalid, so both are ignored
- A reject policy published before anybody read the reports, with the helpdesk still unauthenticated
- Order confirmations on one domain and marketing on another, with only one of them set up
- A free mailbox in the from address, which the bulk sender rules will not accept
Three of those four are somebody being helpful in a hurry. Nobody breaks authentication on purpose, which is exactly why nobody notices until a campaign disappears.
If that's beyond the people you've got, it's the first thing we do on a new account, before a single flow gets rebuilt. What we do inside Klaviyo covers the rest, and the way we build an email system shows where it sits in the order of work.

Theo Tziapouras
Founder and strategy at Engage Commerce, the ecommerce agency for 7 and 8 figure DTC brands.
FAQs

Does Klaviyo set up SPF and DKIM for me?
Klaviyo generates the records and verifies them once they're live, but it can't publish them for you. They go into DNS wherever the domain is managed, which might be Shopify, your registrar or an old agency account. Finding out who holds that login is the step that stalls, so do it first.
Do I need DMARC if SPF and DKIM already pass?
Yes, if you send in bulk. Google and Yahoo both ask bulk senders for a DMARC record, and without one you've no way of seeing who else is sending as your brand. Start on a monitoring policy and leave it there until the reports stop showing you anything new.
What is a sending subdomain, and do I need one?
It's a subdomain used only for marketing mail, such as news.yourshop.com. It keeps campaign reputation away from the order confirmations and password resets that have to arrive whatever else happens. Most Shopify brands should use one, and Klaviyo walks you through creating it.
Will a strict DMARC policy stop my order confirmations?
It will if they're sent from a system you haven't authenticated, which is the usual reason people are frightened of it. That's what the monitoring stage is for: the reports name every service sending as you, including the ones nobody told you about. Fix them all, then tighten the policy.
How soon after fixing this do things improve?
The technical part takes effect on the next send. Reputation is slower, because mailbox providers want a few weeks of clean sending before they revise their opinion of you. Fix the records, keep the sending pattern steady, and don't judge it on one campaign.
Authentication is the cheapest insurance in email
Nobody has ever thanked us for a DMARC record. It's invisible when it works and expensive when it's missing, which is a rotten combination for something that takes an afternoon. Do it before peak season instead of during it, do it once, and write down every system that sends as you. The next person shouldn't have to guess.
Deliverability and UK consent
Getting into the inbox, and staying inside UK GDPR and PECR while you do it.

The soft opt in rules UK ecommerce brands have to follow
What PECR lets you send to past customers, where the line sits, and the record that decides which side of it you are on.
Read it
Email sending domain warm up: changing domains without wrecking the list
Reputation is attached to the domain, not to you. Move it and you start again, so the first question is whether you have to.
Read it
Your email open rate dropped suddenly: what to check, and in what order
Opens are a soft number now. A collapse still means something, and it is almost never the subject line.
Read itWould you rather this was just handled?
Bring your Klaviyo account and the thing annoying you most. We will tell you what we would fix first, on the call, before you spend anything.


Book a call with our founder.
We're all about relationships built on trust, mutual respect and a shared vision for success. If that sounds like your vibe, let's make some waves together 🌊



