Official DNS Guide • E-commerce Platform

Shopify Email & Store Notifications SPF Record Setup & Validator

Configure Shopify SPF record (include:shops.shopify.com), DKIM CNAME records, and prevent order confirmation emails from going to spam.

Quick Answer • Exact Shopify Email SPF Syntax

To authorize Shopify Email & Store Notifications to send emails on behalf of your domain, add include:shops.shopify.com to your domain's single DNS TXT SPF record before the terminating ~all mechanism. The standard record is v=spf1 include:shops.shopify.com ~all.

Live Shopify Email DNS Validator

Test your domain's published SPF, DKIM, and DMARC records via global DoH edge nodes in real time.

Zero-Log Client Evaluation

Understanding Shopify Email & Store Notifications Email Authentication

Shopify requires merchant domains to authenticate SPF and DKIM so order receipts, shipping notifications, and marketing emails reach customer inboxes.

When Shopify Email & Store Notifications delivers outbound emails on your behalf, recipient mail transfer agents (MTAs) at Google, Yahoo, Microsoft, and corporate mail gateways inspect the sender identity. Without a published SPF record explicitly permitting Shopify Email & Store Notifications's IP ranges, these emails trigger SPF Softfail (~all) or Hardfail (-all), severely degrading domain reputation and inbox placement.

Required DNS Records for Shopify Email

Publish the following DNS records in your domain registrar or DNS management console (Cloudflare, AWS Route 53, GoDaddy, Namecheap):

TypeHost / NameValue / TargetTTLPurpose
TXT@v=spf1 include:shops.shopify.com ~all3600Shopify store SPF.

Step-by-Step Setup Instructions

1

In Shopify Admin > Settings > Notifications > Sender email > Authenticate your domain.

2

Shopify provides 4 CNAME records for DKIM and Return-Path.

3

Add "include:shops.shopify.com" to your root SPF record.

4

Click Authenticate in Shopify.

Common Shopify Email SPF Configuration Mistakes

× Customer emails landing in Spam

Cause: Missing Shopify domain authentication.

Fix: Authenticate sender domain in Shopify admin.

Frequently Asked Questions

What is the SPF include for Shopify?

Shopify uses "include:shops.shopify.com".

Why do Shopify order confirmation emails go to spam without domain authentication?

Without domain authentication, Shopify sends emails using its shared infrastructure. The From: header shows your sender email but the underlying DKIM signature and Return-Path are under Shopify's domain, causing DMARC misalignment. Gmail and Outlook increasingly route unauthenticated marketing and transactional email to spam.

What DNS records does Shopify require for full authentication?

Shopify generates 4 CNAME records when you authenticate your sender domain: two DKIM records (typically [token1]._domainkey and [token2]._domainkey), a Return-Path CNAME, and a tracking CNAME. All must be added to your DNS zone through your DNS provider.

Can I use Shopify Email with a Gmail or Outlook domain?

You can configure any email address as your sender address in Shopify, but for proper DMARC alignment, the sender domain must be a domain you control. Free provider domains (gmail.com, outlook.com) cannot be authenticated in Shopify because you cannot add DNS records to those domains.

How does Shopify Email authentication interact with my existing corporate email provider?

If your corporate inbox uses Google Workspace or Microsoft 365, add Shopify's authentication CNAME records alongside your existing Google/Microsoft SPF and DKIM records. The Shopify CNAME records do not conflict with existing records since they use unique host names.

How do I check if my Shopify sender domain is fully authenticated?

Run IncogSay's SPF Checker to confirm include:shops.shopify.com is in your root SPF record. Use the DKIM Checker with your domain and Shopify's assigned selector to verify the DKIM CNAME chain resolves to a valid key. Then confirm your DMARC policy covers the domain.