Skip to content

Scan your domain with 35 DNS and email security checks at zerohook.org.

For your provider

Klaviyo

Klaviyo's branded-sending-domain article generates up to three CNAME or four NS records plus a TXT verification record. Klaviyo says DKIM and SPF for the branded subdomain are enabled through those records rather than a separate apex SPF you invent.

Klaviyo's email-authentication article says senders on Klaviyo's shared domain already pass SPF and DKIM, and that branded domains use the CNAME or NS records from setup. DMARC at _dmarc is configured in the DNS provider; Klaviyo gives v=DMARC1; p=none as an example starting policy.

Static vs dynamic routing

Klaviyo's setup flow offers dynamic routing with NS records at the branded subdomain or static routing with CNAME records. Selector names differ for marketing, transactional, and service send types as listed in Klaviyo's help article.

Klaviyo's troubleshooting guidance says to combine multiple v=spf1 values into a single SPF record when you do add SPF at a host, because RFC 7208 treats more than one version record on the same name as permerror.

DMARC example

Klaviyo's authentication article shows v=DMARC1; p=none as a starting DMARC TXT at _dmarc configured outside Klaviyo in the DNS provider.

Shared Klaviyo sending domains already carry SPF and DKIM; branded domains require the records Klaviyo displays during setup.

RFC 7208 permerror still applies if more than one SPF version TXT is published on the same host name.