TL;DR: Gmail and Yahoo now require SPF, DKIM, and DMARC on every Shopify store that emails customers. Authenticate your domain in Shopify for transactional email, set up a branded sending domain in Klaviyo for marketing, then publish one DMARC record at your root domain that covers both. Start DMARC at p=none, read the reports for a week or two, then tighten to enforcement. Done right, your emails land in the inbox instead of spam.
SPF, DKIM, and DMARC are the three email authentication records that tell inbox providers a message from your Shopify store is really from you, and skipping them is the fastest way for a growing brand to land in spam. If your open rates quietly slipped this year, weak authentication is a likely cause.
Since February 2024, Gmail and Yahoo require every sender pushing more than 5,000 messages a day to a personal inbox to pass SPF, DKIM, and DMARC. Most Shopify brands doing real volume cross that line without realizing it. Miss the setup and your emails get rewritten, throttled, or dropped.
Here is the part most guides skip. A typical Shopify store sends from two places. Shopify handles transactional email like order confirmations, and Klaviyo handles marketing. Both need authentication, and both answer to one DMARC record at your root domain. Get that wrong and you can pass on Shopify while quietly failing on Klaviyo.
This guide walks through the full setup for both, in plain language, with the exact records and the order to add them. Across the Shopify stores we manage at CartStrings, clean authentication is what keeps inbox delivery near 99.8%.
What do SPF, DKIM, DMARC do?
SPF, DKIM, and DMARC are three DNS records that verify your email. SPF lists who is allowed to send for your domain, DKIM signs each message so it cannot be faked, and DMARC tells inboxes what to do when a message fails either check. Together they prove your Shopify emails are legit.
Think of it like ID at a door. SPF is the guest list of approved senders. DKIM is a tamper-proof seal on the envelope, so the receiver knows the contents were not changed in transit. DMARC is the bouncer's instruction card. If a message claims to be from your domain but fails both SPF and DKIM, DMARC decides whether to let it through, send it to spam, or reject it outright.
All three live in your domain's DNS settings, not inside Shopify or Klaviyo. That is why setup happens at your domain host, and why both of your sending tools point back to the same place.
Why does Shopify need this?
Because Gmail and Yahoo now enforce it. Since February 2024 they require SPF, DKIM, and a DMARC record for any domain sending 5,000 or more messages a day to personal inboxes. Shopify stores hit that volume fast, and unauthenticated mail gets throttled, spam-filed, or rejected.
The rules go further than authentication. Gmail wants your spam complaint rate kept under 0.1% and never above 0.3%, one-click unsubscribe on marketing emails, and unsubscribe requests honored within two days. As of November 2025, Gmail ramped up enforcement, so failing mail now sees real temporary and permanent rejections, not just warnings. Google's sender guidelines spell out the full list.
There is also a Shopify-specific catch. If your domain is not authenticated, Shopify rewrites your sender address to something like store+123@shopifyemail.com so your mail keeps flowing. It works, but customers see a generic address instead of your brand, and it quietly caps your deliverability.
How to authenticate Shopify
This covers your transactional email, the order confirmations and shipping updates Shopify sends on your behalf. Here is the setup.
First, set your sender email. In your Shopify admin, go to Settings, then Notifications, and enter your branded address in the Sender email section, for example hello@yourbrand.com.
Next, authenticate the domain. In that same Sender email section, click Email domain authentication. If your domain was bought through Shopify, authentication is already done for you, including DKIM, SPF, and DMARC. If your domain sits on Cloudflare, GoDaddy, or IONOS, Shopify can configure the DNS for you automatically.
For any other host, authenticate manually. Shopify shows you a set of CNAME records to copy into your domain's DNS. Those CNAME records handle both DKIM and SPF, so you do not add a separate SPF TXT record. Add every record shown, since the count can vary. One caution: never delete these CNAME records later. If you do, Shopify resets your sender back to the generic shopifyemail.com address and deliverability drops. Shopify's own guide has the current screens if the layout has changed.
Do I need this for Klaviyo?
Yes. Klaviyo is a separate sending source from Shopify, so it needs its own authentication. In Klaviyo, set up a branded sending domain. That single step adds the DNS records that turn on SPF and DKIM for your marketing email and keep it aligned with your brand.
This is the step that trips up growing stores. Authenticating Shopify covers order confirmations, but your campaigns and flows go out through Klaviyo, and those stay unauthenticated until you set up a branded sending domain there too.
In Klaviyo, go to Settings, then Email, then Branded sending domain. Klaviyo gives you records to add at your DNS host. Dynamic routing uses NS records and is the recommended option, while static routing uses CNAME records. Either way, Klaviyo also hands you one TXT record to verify you own the domain. Add them all, wait up to 24 hours, then click Verify Records until every warning turns green.
The payoff is that both your transactional and marketing email now send from your real domain, so a single DMARC policy can vouch for both. That shared root is the whole reason authentication has to be done in one coordinated pass, not two disconnected ones. This is where an outsourced email team earns its keep, and our deliverability service handles the whole setup end to end.
How to set up DMARC
DMARC is one TXT record at your root domain, and it governs every source that sends as your brand, Shopify and Klaviyo included. That is why you add it once, after both senders are authenticated.
Log in to your domain host and add a TXT record. In the name field, enter _dmarc. In the value field, start with this:
v=DMARC1; p=none; rua=mailto:dmarc@yourbrand.com;
The p=none part means monitor only, which is the right starting policy. It changes nothing about delivery yet, but the rua address collects daily reports showing which sources are passing and failing. Read those for a week or two before tightening anything.
Two rules protect you here. First, keep only one DMARC record. Multiple DMARC records break validation and can push Shopify back to its generic sender address, so if you already have one, edit it instead of adding another. Second, use relaxed alignment. If your record contains adkim=s or aspf=s, switch them to adkim=r and aspf=r, which is friendlier to how Shopify and Klaviyo sign your mail.
Is my setup working?
Check three things. Send a test email and confirm it passes SPF, DKIM, and DMARC in the message details. Watch your DMARC reports for any source that is failing. And monitor Google Postmaster Tools, where your spam rate should stay under 0.1%.
Give DNS changes time first. Shopify records can take up to 48 hours to propagate, and Klaviyo up to 24. Verify inside each platform: Klaviyo's Verify Records button should show green, and Shopify should stop rewriting your sender address.
Then confirm at the inbox. Send yourself a campaign and place a test order, open each in Gmail, and check that the details show your domain passing authentication. Set up Google Postmaster Tools to track domain reputation and spam rate over time, since those numbers, not a one-time test, decide long-term inbox placement.
Once your reports show every legitimate source passing for a couple of weeks, tighten DMARC from p=none to p=quarantine, and later p=reject. That final move blocks anyone trying to spoof your brand. If reading DMARC reports is not how you want to spend your week, a Klaviyo audit will pinpoint exactly what is passing and what is not.
Set it once, benefit later
Email authentication is not glamorous, but it is the foundation everything else sits on. You can write the best campaign of the quarter, and it means nothing if Gmail files it under spam. Get SPF, DKIM, and DMARC right for both Shopify and Klaviyo, and your open rates, revenue, and sender reputation all move in the right direction.
The setup is a one-time job with a long payoff. Authenticate Shopify for transactional mail, set up a branded sending domain in Klaviyo, publish one DMARC record at your root, then tighten it as your reports come back clean. If you would rather hand the whole thing off, book a call and we will lock down your email automations and deliverability together. For more playbooks, browse the CartStrings blog.
Frequently Asked Questions
Does Shopify set up SPF, DKIM, and DMARC automatically?
Only if you bought your domain through Shopify. In that case DKIM, SPF, and DMARC are configured for you. For a third-party domain you authenticate it yourself in Settings, then Notifications, and Shopify sets up SPF and DKIM through CNAME records, but you still add the DMARC record manually.
Do I need authentication if I only use Klaviyo?
Yes. Klaviyo is its own sending source, so it needs a branded sending domain to pass SPF and DKIM. Even if Shopify is authenticated, your Klaviyo campaigns stay unauthenticated until you complete that step. Both sources then share the one DMARC record at your root domain.
How long do DNS changes take to work?
Plan for up to 48 hours, though it is often faster. Shopify records can take up to 48 hours to propagate and Klaviyo up to 24. Use each platform's verify button to confirm, and do not assume it failed if it is not instant.
What DMARC policy should I start with?
Start with p=none. It monitors without affecting delivery and collects reports showing which sources pass and fail. After a week or two of clean reports, move to p=quarantine, then p=reject to block spoofing. Never jump straight to reject, or you risk blocking your own mail.
Can I have more than one DMARC record?
No. A domain must have exactly one DMARC record. Multiple records break validation and can cause Shopify to rewrite your sender address. If you already have a DMARC record from another tool, edit that single record instead of adding a new one.
.avif)



