- Short answer
- A domain bought through Shopify is authenticated for you; a third-party domain needs Shopify's CNAMEs plus your own DMARC TXT.
- If you skip it
- Shopify rewrites your sender address to store+123@shopifyemail.com so campaigns keep sending
- No separate SPF record
- Shopify says its CNAMEs handle DKIM and SPF — no separate SPF TXT record for this purpose
- Automatic is not complete
- Where automatic authentication is available, it sets up the CNAMEs but not a DMARC record — that stays manual
- Only one DMARC record
- Multiple DMARC TXT records make validation fail, and your sender email is rewritten
- Strict alignment breaks it
- An existing DMARC record carrying adkim=s or aspf=s can stop Shopify mail from authenticating
- Who the rule applies to
- Google adds DMARC above 5,000 a day to Gmail; Yahoo declines to publish a number; Shopify states no volume
What Shopify sets up for you, and what stays yours
Where the domain is registered decides how much of this is your job. Shopify splits it three ways, and only the first leaves you nothing to do:
Who adds which record
| Your domain | What Shopify does | What you add |
|---|---|---|
| Bought through Shopify | Configures DKIM, SPF and DMARC for you | Nothing |
| Third-party, automatic path (Cloudflare, GoDaddy, IONOS) | Sets up the CNAMEs that carry DKIM and SPF | The DMARC record — automatic authentication skips it |
| Any other third-party domain | Displays the records to add in a modal | Every CNAME shown, plus one DMARC TXT record |
Shopify Help Center — Setting up your email; Sender email rewrites. Read August 26, 2026.
Both bottom rows are third-party domains, and there Shopify names two requirements rather than one. It frames them as what keeps your own sender address: "To prevent your sender email from being rewritten to store+123@shopifyemail.com, your domain requires both of the following records", and the two it then lists are CNAME records and a DMARC record. The shortcut in row two — what Shopify calls automatic authentication — covers the CNAMEs and stops there:
Automatic authentication sets up your CNAME records to handle DKIM and SPF authentication, but doesn't configure a DMARC record. You must manually add a DMARC record to your domain.
That quote is scoped to the two third-party rows, and the page as a whole is scoped to mail Shopify Messaging sends. If your campaigns leave through an email platform instead, that tool publishes its own records — our Klaviyo guide covers the DNS side of deliverability there.
Which records a third-party domain needs
On a third-party domain the records appear in a modal — unless your domain or its DNS sits with one of the three providers in the next section — and the CNAMEs in it are not separate errands: Shopify calls them "CNAME records (which handle the required DKIM and SPF authentication)". No separate SPF TXT record is required for this purpose — Shopify's sentence, closing qualifier included, and that qualifier keeps it about the sender address you are authenticating here.
How many CNAMEs? Shopify does not commit to a count, which is exactly the detail third-party tutorials most often invent:
The number of records may vary, so you must add all records displayed in the modal.
DMARC is the other half: a single TXT record, minimum v=DMARC1; p=none. That is a monitoring policy — it asks receivers to report on your mail, not to reject it.
Then wait: "Changes can take up to 48 hours to complete", so a store still sending from the wrong address an hour later is not broken.
When Shopify can add the CNAMEs for you
Three providers have an automatic path: Cloudflare, GoDaddy and IONOS. Shopify states the condition twice on one page, and the two are not synonyms — "For third-party domains hosted on Cloudflare, GoDaddy, or IONOS" against "If you purchased your domain from Cloudflare, GoDaddy, or IONOS". Hosting DNS at a provider and buying the domain there are different situations, and Shopify does not reconcile them.
Neither formulation changes what arrives: the DMARC record is not part of it.
One list is easy to mistake for another: Shopify's domain-connection page names fourteen providers, but it covers pointing a domain at your store with A, AAAA and CNAME records, and mentions email authentication for none of them.
What a later move costs you is not something we could source: none of the five Shopify domain and email pages we read on August 26, 2026 describes what happens to a working setup when the domain changes DNS host. What Shopify does document is the consequence of losing the records: removing the CNAMEs "can cause deliverability issues, including bounces", and Shopify resets your sender address to its own fallback "until the records are restored at your third-party domain manager". Re-checking both record types after a move is the precaution that removal rule implies.
What breaks a DMARC record you already have
Plenty of stores already publish DMARC, added for Google Workspace or by an email platform. Two documented details decide whether that record also works for the mail Shopify sends. The first is alignment mode:
If your domain already has a DMARC record, then ensure that it doesn't include adkim=s or aspf=s. These strict alignment settings can prevent your emails from being properly authenticated when sent through Shopify.
The second is arithmetic: there may be only one. A second record is easy to acquire — one from the tool that asked for it, one added by hand — and Shopify does not read the pair as a stricter single policy. "Having multiple DMARC TXT records causes validation to fail," and the fallback is the rewritten address below. Check both before concluding the CNAMEs failed.
If you skip these records, Shopify rewrites your sender address
Nothing stops, and that is the part merchants misread. Shopify keeps the campaigns going under a different name: "If you take no action, then your sender email will be rewritten to store+123@shopifyemail.com to meet the minimum requirements so that you can continue sending emails to your customers without interruption." The cost lands on the brand, not on delivery.
Whether the requirement reaches your store is where the three sources differ in scope. Shopify states it with no volume qualifier: "Gmail and Yahoo require you to authenticate your domain and have a DMARC record to send emails to customers from a branded email address." Google publishes a number, but only for its stricter tier: every sender to Gmail has needed SPF or DKIM since February 1, 2024, and DMARC is what Google adds above 5,000 messages per day to Gmail accounts. Yahoo names none, deliberately:
A "bulk" sender is classified as an email sender sending a significant volume of mail. We will not specify a volume threshold.
So a small sender reasoning "I am under five thousand a day" borrows Google's line for a company that refuses to draw one, and for a Shopify page that never mentioned volume. Yahoo asks every sender to implement SPF or DKIM at a minimum, and adds DMARC for bulk mail. On a third-party domain, whichever tier you fall in, Shopify's own instruction is the same two records: every CNAME the modal shows, and one DMARC TXT of at least v=DMARC1; p=none.
This article was written entirely by AI under human editorial direction. The editor sets the topic and structure, runs multi-stage validation on facts, links, and interactive elements, and verifies the output is useful from a business perspective. All claims are checked against official Shopify sources. Details may change — always confirm critical data at shopify.com.
Editorial Policy