On this page
  1. What Shopify sends as your domain
  2. The CNAME records Shopify asks for
  3. Does Shopify still need an SPF include?
  4. The DMARC record Shopify requires
  5. The five situations Shopify documents
  6. Check your domain
  7. Sources

Shopify authenticates the domain of your store's sender email with CNAME records you add at your DNS host, and it requires a DMARC record on that domain. Without both, Shopify's email setup page (opens in a new tab) rewrites your sender address to store+123@shopifyemail.com so mail keeps flowing. The CNAME records handle SPF and DKIM for the sender address, so Shopify does not ask you to add a separate SPF TXT record. Add the CNAMEs shown in your Shopify admin, publish a DMARC record starting at p=none, and the rewrite stops.

What Shopify sends as your domain

Two settings control store email. Shopify's setup page (opens in a new tab) describes the store email as the address you signed up with, listed under Settings, General, and the sender email as the customer-facing address under Settings, Notifications, used as the From address on automatic notifications, order confirmations and any marketing emails sent from the store. Since 1 February 2024, Gmail and Yahoo require the domain to be authenticated and to carry a DMARC record before Shopify can send to customers from a branded address.

If you take no action, Shopify rewrites the sender to store+123@shopifyemail.com, where the number is unique to your store, to meet the minimum requirements. The same rewrite happens when the authentication records are missing. Shopify also notes that some mail hosts reject addresses containing wording such as no-reply or noreply, so pick a sender address people can reply to.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.

The CNAME records Shopify asks for

The records come from your Shopify admin. On Shopify's setup page (opens in a new tab), the path is Settings, Notifications, then in the Sender email section click Email domain authentication or authenticate your domain. Shopify offers automatic authentication for domains on Cloudflare, GoDaddy or IONOS, which sets up the CNAME records for DKIM and SPF but does not create a DMARC record; otherwise the modal shows the CNAME records to enter at your third-party domain manager. The number of records varies, so add every record displayed. Changes can take up to 48 hours, and if verification fails, compare what you entered with what the admin showed.

The records go on the domain of the sender address: for info@example.com, add them to example.com. No IP addresses are needed; Shopify states the CNAME records are sufficient for authentication. Your store must be on an active paid plan, since adding CNAME records is not possible for client transfer stores, dev stores or stores on the Pause and Build plan. Do not remove the records later: Shopify warns that removing them can cause deliverability issues including bounces, and that Shopify Email resets the sender to store+123@shopifyemail.com until the records are restored. A domain purchased through Shopify has DKIM, SPF and DMARC configured automatically.

Does Shopify still need an SPF include?

No. Shopify's setup page (opens in a new tab) is explicit: the CNAME records added during domain authentication handle SPF automatically for the sender email address, and you do not need to add a separate SPF TXT record for this purpose. If you were once told to add include:shops.shopify.com to your root SPF record, check what it points at: checked against live DNS, shops.shopify.com publishes v=spf1 ~all, a record that lists no sending servers. RFC 7208 (opens in a new tab) counts every include toward the limit of 10 DNS lookups per evaluation, so that include spends a lookup on an empty list.

Your root domain may still need an SPF record for whoever sends your everyday mail, such as Google Workspace. Keep it to one record: RFC 7208 section 3.2 (opens in a new tab) forbids a domain from having multiple records that an authorization check would select, and under section 4.5 (opens in a new tab) a receiver that finds more than one returns permerror. If Workspace receives your mail, the Google Workspace guide covers that side.

The DMARC record Shopify requires

DMARC (Domain-based Message Authentication, Reporting, and Conformance (opens in a new tab)) tells receivers what to do with mail that fails SPF and DKIM and where to send reports. Shopify's setup page (opens in a new tab) gives v=DMARC1; p=none as Shopify's default DMARC record and the steps: add a TXT record named _dmarc (some hosts add the domain part themselves, giving _dmarc.example.com) with that value. Your domain must have only one DMARC record; a second one makes DMARC validation fail and your sender may be rewritten to store+123@shopifyemail.com again, so update an existing record rather than adding another. If your existing record has adkim=s or aspf=s, Shopify recommends removing them or changing them to r for the best deliverability with Shopify.

A record with a reporting address is the better starting point, because the reports show you which services send as your domain. Build it in the DMARC generator and publish it at _dmarc.example.com:

v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com

RFC 7489 (opens in a new tab) defines p=none as a request for no specific delivery action and requires the v tag, with the value DMARC1, as the first tag, with the policy covering subdomains unless sp says otherwise. If a checker reports no record, see No DMARC record found; for what p=none does and the safe order to move to quarantine or reject, see DMARC policy not enabled.

The five situations Shopify documents

Shopify's sending-email page (opens in a new tab) requires both the CNAME records and a DMARC record of at least v=DMARC1; p=none to prevent the rewrite, and walks through five cases.

Situation What Shopify says to do
The sender domain belongs to a third party and you have no DNS access, for example name@gmail.com Use your own domain
Domain bought elsewhere, not yet authenticated Add the CNAME records; Domain Connect can do it on Cloudflare, GoDaddy or IONOS
Domain bought elsewhere, authenticated, but no DMARC record Add a DMARC record
Domain already DMARC-protected but without the CNAME records Add the CNAME records for DKIM and SPF; no separate SPF TXT record is needed
Domain bought through Shopify Nothing: DKIM, SPF and DMARC are configured automatically, and v=DMARC1; p=none is inserted if there is none

The page gives the admin path for adding a custom TXT record: Settings, Domains, Manage in the DNS settings section, then Add custom record, TXT record. Opting out of that record brings the rewrite back.

Check your domain

The free SPF, DKIM and DMARC check reads the public DNS records of the domain you enter and reports each as pass, warning, fail or error, flagging a missing DMARC record, a policy of none with no reporting address, and an SPF record with a soft fail or too many lookups. For DKIM it looks under commonly used selectors; if your provider uses a different selector, the key is there but the check cannot see it. A DNS finding shows how the domain is set up, not where a particular message landed.

Sources

Tools for this

Frequently asked questions

Why do my Shopify notifications show store+123@shopifyemail.com?

Shopify rewrites the sender address to store+123@shopifyemail.com when the sending domain has no authentication records, has no DMARC record, or has more than one DMARC record. Add the CNAME records and a DMARC record and the rewrite stops.

Do I need both the Shopify CNAMEs and a Google Workspace SPF record?

Yes, if Google Workspace sends your everyday mail. The Shopify CNAMEs handle SPF and DKIM for mail Shopify sends; your mailbox provider still needs its own SPF record at the root of the domain. Keep a single SPF record there.

Will adding DMARC block my Shopify emails?

Not at Shopify's default of p=none, which asks receivers to take no action and only enables reporting. Shopify does ask you to avoid adkim=s and aspf=s, the strict alignment settings, because they can stop Shopify's mail from authenticating.

Check your domain now

See the SPF, DKIM and DMARC records your domain publishes and what to fix first. Free, no account needed.