Search cleanup
Spam pages are showing up
Unknown casino or spam pages need evidence, access review and careful cleanup.
Read the checklist →EMAIL DELIVERY
If order confirmations or shipping updates land in spam, start with the sender domain. Shopify uses the Sender email in Settings > Notifications for customer-facing messages, including automatic order confirmations. If that address is on your own domain, the domain needs to be authenticated correctly.
This is a fix you can work through yourself. Make one change at a time and keep a copy of the DNS records before editing them.
In Shopify admin, open Settings > Notifications and find Sender email. Confirm that it is an address on the domain you want customers to see. Send yourself a test notification and check the From address. A sender that has been rewritten to a Shopify address is a sign that the custom domain authentication needs attention.
Shopify says Gmail and Yahoo require domain authentication and a DMARC record for messages sent to customers from a branded address. Shopify may rewrite the sender to a store-specific Shopify address when the requirements are not met. That can make the message look different from the address customers expect.
Return to Settings > Notifications and open Email domain authentication. If your domain is eligible for automatic authentication, follow Shopify's instructions. Otherwise choose manual authentication and copy every CNAME record shown in Shopify into the DNS manager for the domain used by the Sender email.
Shopify says these CNAME records handle the required SPF and DKIM authentication for its sender address. Do not invent a record or add an IP address because a generic guide told you to. Copy the host and value exactly as Shopify displays them. If your domain host adds the domain name automatically, check that it has not been duplicated in the host field.
DNS changes can take up to 48 hours according to Shopify. During that time, do not keep replacing records. If verification fails, compare the records in your DNS manager with the records currently shown in Shopify admin.
Shopify's automatic authentication sets up CNAME records for SPF and DKIM but does not add DMARC. At your domain host, add one TXT record with the host name _dmarc. Shopify documents v=DMARC1; p=none; as its default example.
Use only one DMARC record for the domain. Shopify warns that multiple DMARC TXT records cause validation to fail and can lead to the sender being rewritten again. If a DMARC record already exists, edit the existing one only if you understand what it does. Do not create a second record to try to override it.
Google's sender guidance says every sender to personal Gmail accounts must use SPF or DKIM. Google recommends setting up SPF, DKIM and DMARC for the domain, and says messages that are not authenticated can be marked as spam or rejected. Authentication helps, but it does not guarantee that every recipient will place every message in the inbox.
Write down every service that sends mail from the domain, such as Shopify Email, a help desk, a review tool or a newsletter service. Each service may provide its own DKIM or SPF instructions. Google says that if you use an email service provider, you should verify that it authenticates your domain with SPF and DKIM.
Be careful with the SPF record. Do not add a second SPF TXT record because another tool needs to be included. Ask the tool's documentation or support for the correct way to add its sender to the existing record. If you are unsure which service is sending a message, open the message's original headers and note the authentication results before changing DNS.
Place a small test order using an inbox you control, or use Shopify's available notification preview. Check both the inbox and spam folder. Confirm the visible From address and whether the notification is the expected Shopify order message. Test again after DNS changes have propagated.
If the message still goes to spam after authentication is in place, keep the message headers and the recipient provider's error or spam notice. Those details tell you whether the problem is an authentication failure, a sender address change or a recipient filtering decision. Do not keep changing DNS without that evidence.
Get help if you have two SPF records, more than one DMARC record, a domain that fails verification, or more than one service sending from the same address. DNS mistakes can affect other mail from the domain. A careful audit is also useful when order notifications work for one recipient but not another and you need to compare the original headers.
A one-bug Tidewell fix is $299, and larger work gets a written quote ($400 to $1,500). If the cause is unclear, a written diagnosis is $99 and is credited toward the fix within 30 days if you proceed. The scope is agreed before DNS access is needed. We can document the existing records, apply the provider's records and test the Shopify notification flow.
COMMON PROBLEMS
Search cleanup
Unknown casino or spam pages need evidence, access review and careful cleanup.
Read the checklist →Email delivery
Check sender authentication, DNS and notification headers before changing records.
Read the checklist →Merchant Center
Audit store details, policies and product data before requesting another review.
Read the checklist →