Fix Klaviyo emails going to spam

When Klaviyo campaigns start landing in spam, the cause is usually specific to how Klaviyo is configured, not your subject lines. This guide covers the klaviyomail.com alignment trap, branded sending domain setup, Smart Sending and Shopify sync side effects, and how to test a real Klaviyo campaign send with Unspam. The single most important fix: stop sending from Klaviyo's shared domain.

Why Klaviyo emails land in spam.

01

Your DKIM signature still says klaviyomail.com

Out of the box, Klaviyo sends from its shared domain, so DKIM signs klaviyomail.com and Gmail shows "via klaviyomail.com" next to your brand name. That breaks DMARC alignment, and since the February 2024 Google and Yahoo rules, anyone sending 5,000+ emails a day to Gmail must send DMARC-aligned mail. Klaviyo's own docs call a branded sending domain a requirement for bulk senders. Set one up under Settings > Domains, then confirm the DKIM d= domain on a live send.

02

You activated a branded sending domain, then kept full volume

A new send.yourbrand.com subdomain has zero reputation with Gmail and Yahoo. Flip it on and immediately blast your full list, and providers see an unknown domain at high volume, a classic spam pattern. Warm the new domain the way Klaviyo's deliverability guidance recommends: start with your most engaged segment (30 to 60 day openers and clickers) and widen the audience over two to four weeks.

03

Shopify sync filled Klaviyo with profiles that never opted in

The Shopify integration syncs customer profiles in real time, including buyers who never subscribed and old Accepts Marketing imports from before Klaviyo switched to Shopify's subscription model. Target a raw list instead of a segment and you mail stale, never-engaged addresses, which drives bounces and complaints. Build a segment combining consent with recent engagement conditions and make it your default campaign audience.

04

No sunset flow, so dead profiles drag your domain down

Klaviyo never removes unengaged profiles for you, and you pay to keep them active. Profiles with no opens or clicks in 90 to 180 days are the most likely to complain or decay into spam traps. Build a sunset flow off an unengaged segment, send a final win-back, then suppress non-responders so Klaviyo stops mailing them while keeping their data.

05

Your spam complaint rate crossed Gmail's line and nothing stopped the send

Gmail wants complaints under 0.1% and starts blocking bulk senders around 0.3%. Klaviyo reports complaints after the fact in each campaign's Deliverability tab and in the deliverability hub, with per-provider breakouts, but it will not halt a bad send for you. Most providers, Gmail above all, do not share complaints back with ESPs, so Klaviyo's numbers undercount: monitor your real Gmail spam rate in Google Postmaster Tools.

06

Shared infrastructure ties you to other Klaviyo senders

Unless you send around one million marketing emails a month and pass Klaviyo's review, you are on shared IPs, and by default your links run through shared tracking domains like trk.klclick.com. You cannot control the pool, but domain reputation is yours: a branded sending domain plus dedicated click tracking puts your own domain on every signal filters check. A dedicated IP is not the fix at typical volumes; thin volume on a dedicated IP performs worse than a healthy shared pool.

How Klaviyo authenticates your mail.

Klaviyo signs every send itself, so there is nothing to paste into your root SPF record. Authentication lives or dies on one thing: whether you have activated a branded sending domain under Settings > Domains.

record default the problem the fix
DKIM Without a branded sending domain, Klaviyo DKIM-signs mail with its shared klaviyomail.com domain, not your From domain. The DKIM d= domain never matches your From domain, so DMARC alignment fails and Gmail shows "via klaviyomail.com" beside your sender name. Add a branded sending domain via Settings > Domains > Add Domain; static routing generates 3 CNAME records (two are DKIM selectors like km1._domainkey) plus a TXT verification record, dynamic routing uses 4 NS records instead.
SPF The Return-Path (bounce) domain is Klaviyo-managed, so SPF always passes, but against Klaviyo's domain rather than yours. SPF passes without alignment, which is why DMARC reports show SPF pass but alignment fail on shared-domain sends. Activating a branded sending domain moves the Return-Path to your subdomain; do not add a Klaviyo include to your root SPF, it changes nothing because Klaviyo controls the bounce domain.
DMARC Klaviyo works without any DMARC record on your domain, and many stores never publish one. Google and Yahoo require at least p=none on bulk senders' From domains, and an enforcement policy (quarantine or reject) without aligned DKIM sends your own campaigns to spam. Publish v=DMARC1; p=none with an rua reporting address; the Add Domain wizard in Settings > Domains includes a DMARC setup step, and you tighten the policy once reports run clean.
Tracking domain Opens and clicks route through shared Klaviyo tracking domains such as trk.klclick.com until you change it. Every link points at a domain you share with thousands of other senders, and the mismatch with your From domain reads as phishing-adjacent to filters. On a paid plan, go to Settings > Domains > Click tracking domains > Add domain and publish the CNAME (for example trk.yourbrand.com pointing to dct.klaviyodns.com).

Once you have updated these records, confirm they pass with Unspam's free SPF checker, DKIM checker, and DMARC checker.

How to test a Klaviyo campaign with Unspam.

Klaviyo's Preview & test button does not behave like a campaign send: click tracking is not applied, unsubscribe links are placeholders, and the mail goes out ad hoc instead of through your normal campaign path. The only honest test is a real campaign send to a seed address.

  1. 01

    Get your Unspam seed address

    Start a spam test or inbox placement test in Unspam and copy the test address it generates. Placement tests include seed addresses across Gmail, Outlook, Yahoo, Zoho, ProtonMail and AOL.

  2. 02

    Create a seed list in Klaviyo

    Go to Audience > Lists & segments, create a new list named something like Deliverability seeds, and add the Unspam address as a profile.

  3. 03

    Clone the real campaign and point it at the seed list

    In Campaigns, clone the campaign you are worried about and select the seed list as the recipient. In the recipients step, turn off Smart Sending for this campaign, or repeat tests within 16 hours get silently skipped.

  4. 04

    Send it for real, not via Preview & test

    Use the normal Send or Schedule action so the email leaves through your actual sending domain with live click tracking and one-click unsubscribe headers, exactly like a customer send.

  5. 05

    Read the results in Unspam

    Check the spam score, the SPF, DKIM and DMARC results on the live send (the DKIM domain should be your branded subdomain, not klaviyomail.com), placement per provider, client previews and the heatmap. The AI fix assistant flags what to change before the real send.

The same test renders your campaign in 50+ real email clients, Gmail, Outlook, Apple Mail, iPhone, and Android among them, each in light and dark mode, via email client previews, so you confirm placement and rendering in one pass.

Klaviyo features that quietly affect delivery.

Smart Sending skips recipients and never reschedules them

Smart Sending is on by default and skips anyone who already received an email from you within the last 16 hours, including seed addresses and flow emails. Skipped messages are not queued for later; they are simply never sent. Adjust the window in your account's email settings or disable it per campaign when testing.

Klaviyo suppression does not sync back to Shopify

Unsubscribes update Shopify consent, but profiles you suppress in Klaviyo stay marked as subscribed in Shopify. Any other app reading Shopify consent, or a careless re-import, can resurrect addresses you suppressed for bouncing or complaining. Treat Klaviyo's suppression list as the source of truth and audit imports against it.

Test emails skip click tracking and live unsubscribe links

Mail sent through Preview & test gets no tracked links and no functional unsubscribe link, so it neither looks nor behaves exactly like a campaign. A test that reaches the inbox proves little, and one that hits spam may just reflect odd ad hoc timing. Validate with a real campaign send to seed addresses instead.

Dedicated click tracking requires a paid plan

Until you activate it, every link resolves through shared Klaviyo tracking domains such as trk.klclick.com, whose reputation you share with every other sender on them. Setup lives in Settings > Domains > Click tracking domains and needs one CNAME pointing to dct.klaviyodns.com. Free accounts see Upgrade required and stay on the shared domain.

What real Klaviyo senders run into.

The deliverability problems Klaviyo senders hit most often, each with the fix that resolves it.

Our double opt-in confirmation emails land in spam, so half our signups never confirm

The welcome email arrives fine but the double opt-in confirmation lands in spam, so many signups never confirm and the store loses them. It happens because the account-level Default From is still a free-provider address (a @gmail.com or @yahoo.com), which fails authentication under the 2024 Google/Yahoo rules, and the confirmation hits brand-new, cold recipients.

The fix In Klaviyo, open the account menu (bottom left) and go to Settings > Account > Contact Information > Organization, then set the Default From / Reply-To to an address on a domain you own. Never use a @gmail.com, @yahoo.com, or other free-provider address, because since the Feb 2024 Google/Yahoo rules a free-provider From fails authentication. Pair it with a verified branded sending domain (Settings > Domains) so the confirmation is DMARC-aligned, and note that changing the Default From only affects emails created afterward, so update the existing confirmation template too. Make sure that template is not text-thin: a bare "click to confirm" with no real content reads as phishing to filters.

Our branded sending domain showed active, then quietly reverted to klaviyomail.com and mail started hitting spam again

A branded sending domain verifies and shows Active, then disconnects on its own, and Klaviyo silently falls back to the shared klaviyomail.com domain, so deliverability craters weeks later with no obvious cause. The usual trigger is Cloudflare proxying (orange cloud) on the Klaviyo records, or DNS drift like a missing trailing dot on a CNAME value, causing periodic re-verification failures.

The fix In Cloudflare, set every Klaviyo DNS record (the km CNAME selectors, the tracking CNAME, and the TXT verification record) to DNS only (gray cloud), never Proxied, and leave them that way permanently, since Klaviyo requires proxying stay off even after verification succeeds. Re-check the exact host and value against Settings > Domains, watching for a missing trailing dot at the end of a CNAME value that makes some providers auto-append your root domain. If dynamic (NS) routing keeps failing to propagate, switch to the static (CNAME) setup as a fallback, noting that Klaviyo officially recommends dynamic routing for best performance. Confirm propagation with dnschecker.org or MXToolbox, then verify the DKIM d= domain on a real send is your branded subdomain, not klaviyomail.com.

We switched this list to single opt-in to protect signup metrics, and bots list-bombed the form, wrecking our bounce and complaint rates

Store owners who set a list to single opt-in report waves of fake and mistyped addresses flooding their signup forms and abandoned-checkout flow, driving hard bounces, spam-trap hits, and complaints that tank domain reputation. Klaviyo lists are double opt-in by default, so list-bombing bites hardest on lists deliberately set to single opt-in and on embedded or custom-coded forms where Klaviyo's built-in bot protection does not fully apply.

The fix Re-enable double opt-in on the affected list (Lists & segments > the list > Settings > Consent > Opt-in Process) so unconfirmed bot addresses are never mailed; this is the single most effective defense because only confirmed subscribers are added. Know that Klaviyo's native protection is only a reactive CAPTCHA shown to already-suspicious IPs, so it kicks in after an attack starts and does not fully cover embedded or custom-coded forms; for proactive protection you must add Google reCAPTCHA plus a honeypot field to your own form's HTML. To clean up the damage, build a segment of profiles that can receive email marketing, have received email 3 or more times in the last 180 days, and have zero opens, zero clicks, and zero placed orders all-time, then suppress them.

Apple's fake opens keep dead subscribers on our list, and our sunset flow never fires

With roughly half of opens now from Apple Mail Privacy Protection, Apple's servers pre-load Klaviyo's tracking pixel on delivery and log an open whether or not anyone read the email. This breaks any logic built on opens: engaged segments fill with ghosts, sunset flows that suppress "no opens in 90 to 180 days" never trip for Apple users, and win-back flows fire on phantom re-engagement, so unengaged addresses keep getting mailed.

The fix Stop defining engagement on opens. Klaviyo flags every open with a boolean property called Apple Privacy Open, set to True for MPP-generated opens, so add the filter "where Apple Privacy Open equals False" to any Opened Email condition and rebuild engaged segments, sunset triggers, and win-back flows around clicks and real purchase behavior. Clicks are far harder for Apple MPP to fake, since MPP pre-fetches images, not links. For definitive suppression decisions, base them on server-side behavioral events (viewed-product, added-to-cart, placed-order) that fire through Klaviyo's Track API rather than from an inbox pixel, since those are genuinely immune to MPP pre-fetching.

A deliverability tester flags your shared Klaviyo IPs as blocklisted, and you assume your sending is broken

Senders run GlockApps or a similar tester, see a high spam rate, and trace it to blocklist hits on Klaviyo's shared sending IPs, even though SPF, DKIM, and DMARC all pass and their own domain is clean. Because Klaviyo routes across a shared pool, some of those IPs almost always carry a hit from a noisy neighbor, and the same test on other ESPs shows the same thing.

The fix Check which blocklist before reacting. Minor ones like Hostkarma or all.s5h.net do not affect inbox placement, and you can confirm by checking your bounce messages for any mention of them. Shared-IP hits are noise that averages out, since real campaigns distribute across many IPs, so do not switch to a dedicated IP unless you consistently send well above 50k to 100k per month, because thin volume on a dedicated IP earns worse reputation than a healthy shared pool. Domain reputation, not IP, drives Gmail placement, so if your auth is aligned and your domain is clean you are in good shape. Get an honest read by seeding real inboxes during an actual campaign rather than from an isolated tester snapshot.

Klaviyo deliverability, answered.

Why does Gmail show "via klaviyomail.com" next to my sender name?

Your account is still on Klaviyo's shared sending domain, so the mail is signed by klaviyomail.com instead of your own domain. Gmail flags the mismatch with the via label. Set up a branded sending domain in Settings > Domains and the label disappears once the domain is verified and active.

Do I need to add Klaviyo to my domain's SPF record?

No. Klaviyo controls the Return-Path domain, so SPF is evaluated against Klaviyo's infrastructure and already passes. Adding an include to your root SPF does nothing for alignment. The fix that matters is the branded sending domain, which aligns DKIM and moves the bounce domain to your subdomain.

My open rates dropped right after activating my branded sending domain. Did I break something?

Probably not. Your new sending subdomain has no reputation yet, so providers throttle it until it earns trust. Warm it by mailing your most engaged segments for two to four weeks before returning to full volume, and watch the per-provider breakouts in Klaviyo's deliverability hub while it builds.

Klaviyo test emails land in spam but real campaigns seem fine. Which one do I trust?

Neither, on its own. Test sends skip click tracking, use placeholder unsubscribe links, and go out at odd ad hoc times, all of which changes how filters score them. The reliable signal is a real campaign send to seed addresses, then reading authentication and placement on that exact send.

Can Unspam connect to my Klaviyo account and test campaigns automatically?

No. Unspam does not integrate with Klaviyo's API or any other ESP API. The workflow is manual by design: add Unspam's test address to a Klaviyo list, send a real campaign to it, and read the results in Unspam. That is the only way to test the exact mail your customers receive.

Will a dedicated IP get me out of the spam folder?

Almost certainly not. Klaviyo grants dedicated IPs case by case, generally to senders doing around one million marketing emails a month with strong existing metrics, and low volume on a dedicated IP performs worse than a healthy shared pool. Modern filtering weighs domain reputation heavily, so fix authentication, segmentation and complaint rate first.

Klaviyo platform details were verified against publicly available documentation in June 2026 and may have changed since. Klaviyo is a trademark of its respective owner. Unspam is not affiliated with or endorsed by Klaviyo.

Test your next Klaviyo campaign before your subscribers do.