Security Architecture Overview: shopify.com
Shopify powers millions of merchant storefronts globally. The primary shopify.com domain operates under strict DMARC p=reject to protect merchants from platform impersonation attacks.
Key Anti-Spoofing & Cryptographic Highlights
Frequently Asked Questions
How does Shopify protect store owners from phishing?
Shopify enforces DMARC p=reject and signs all platform communications with verified DKIM keys.
What is the most common Shopify merchant phishing attack?
The most common attack is a fake "your store has been suspended" or "new login detected" email, designed to harvest Shopify admin credentials. Since shopify.com enforces p=reject, these emails typically originate from lookalike domains like shopify-admin.com.
What SSL certificate authority does shopify.com use?
Shopify.com is served through Cloudflare's edge network, so SSL certificates are issued by Cloudflare Inc ECC CA-3. This uses ECC (Elliptic Curve Cryptography) P-256, which provides equivalent security to RSA-3072 at faster performance.
What does Shopify's SPF record include?
Shopify.com's SPF includes both include:shops.shopify.com (for Shopify platform mail) and include:_spf.google.com (for Google Workspace staff email), terminating with ~all.
How old is shopify.com?
Shopify.com was registered on March 11, 2004, making it over 22 years old. Shopify's age and consistent DMARC/DKIM enforcement contribute to its high deliverability reputation with all major inbox providers.
Can a Shopify merchant's store email be spoofed?
A merchant's custom domain email (e.g. orders@mystore.com) depends entirely on that merchant's own DNS configuration. IncogSay's SPF, DKIM, and DMARC checkers allow merchants to audit their own domain authentication before configuring Shopify email sending.