- Short answer
- Look for official sender domains such as @shopify.com; Shopify Support won't ask for your password; when in doubt, contact Support directly.
- Links that point to shopifysvc.com
- Safe to click when Shopify sends through a trusted sender service.
- Where Shopify requests sensitive documents
- Only through a secure upload page starting with app.shopify.com or .shopify.com.
- Reporting a fake
- Forward it to phishing@shopify.com.
- Already clicked the link
- Change your Shopify password, activate two-step authentication, contact Shopify Support.
What does a real Shopify email look like?
Shopify's phishing guide says it "will only send emails from official domains such as @shopify.com, @email.shopify.com, @em.shopify.com, and @shopify-billpay.melio.com." Mail from public services such as Gmail, Yahoo, Apple mail or Hotmail isn't from Shopify. When Shopify delivers through a trusted sender service, links can include the domain shopifysvc.com, which is safe to click.
Some alarming emails are real. If Shopify doesn't recognize a device used for login, you get an email with the subject line "A new device has logged in to your Shopify account". When its security systems detect unusual activity, Shopify locks account access and sends a ten-digit code to your account email.
What will Shopify never ask you for by email?
Whatever the email says, Shopify never asks for sensitive information "directly through an email message that is a text or image, or as a file attachment." And Shopify Support doesn't ask for your Shopify password. Shopify only requests sensitive documents through a secure upload page that starts with app.shopify.com or .shopify.com.
When in doubt, Shopify says to contact Support "directly through official channels for confirmation." If someone then calls as Support, Shopify Support doesn't make outbound phone or video calls on any Shopify plan — see where fake support numbers come from.
What if you already clicked a phishing link?
Already clicked a link? The phishing guide lists three steps in order: change your Shopify account password, activate two-step authentication, then contact Shopify Support to check for any unauthorized access.
Typed your password into the page behind that link? If you think your account has been compromised, Shopify's steps start with Support: contact Shopify Support immediately, then change the password of the email you log in to Shopify with, then your Shopify password — reset it if you can't log in. Shopify's checklist for a compromised account also has you review your staff or collaborator accounts and their permissions.
To check which devices have recently accessed your account, open your profile's Security page from the Shopify admin: its Devices section lets you log out any device you don't recognize.
Forward any phishing message to phishing@shopify.com: by building a record of attacks directed at merchants, Shopify can work to better protect you.
This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.
Editorial Policy