CLEAR SCOPE. FIXED PRICE. WRITTEN HANDOFF.
TidewellShopify systems repair

SHOPIFY DOMAINS

Shopify SSL pending or domain not connecting: what to check

Short answer: after you connect a domain, Shopify says it can take up to 48 hours for the TLS certificate to be issued, and an "SSL pending" or "TLS pending" status shows in your admin during that time. If it has been less than 48 hours, check your DNS records are right and wait. If it has been longer, or the status says "SSL unavailable", the cause is usually a setting at your domain provider: a wrong record, a CAA record that blocks certificate authorities, DNSSEC, or a proxy.

SSL and TLS are used interchangeably here. They mean the certificate that gives your store the padlock.

Step 1: Work out how long it has been

For the pending status, Shopify's advice is to wait 48 hours for DNS propagation and certificate provisioning. If you connected the domain yesterday, do not keep changing records every hour. Fix what is wrong once, then leave it. (Constantly editing records is our own advice, not something Shopify's page says, but it makes it hard to tell what worked.)

Step 2: Check the three DNS records

Log in to the company where you bought the domain (not Shopify, unless you bought it there) and open the DNS settings. Shopify needs three records:

  • A record for the root domain, pointing to Shopify's IP address.
  • AAAA record for the root domain, pointing to Shopify's IPv6 address.
  • CNAME record for www, pointing to Shopify's hostname (it ends with a dot).

Copy the exact values from your own Shopify admin, where you connect the domain, or from Shopify's current domain help page. Do not copy them from a blog post or from this page. Shopify's values can change, and one wrong digit is enough to stop the domain connecting.

Shopify's page also covers a few record problems on their own. Make sure you do not have a wildcard record (*.yourdomain.com) pointing to Shopify. Shopify says it is not supported and can interfere with your site, and to set records for each specific subdomain instead. If the admin says it cannot fetch a record, Shopify's advice is to check your DNS settings, wait up to 48 hours, and contact Support if it persists.

Step 3: Look at any CAA records

CAA records say which companies may issue certificates for your domain. If you use them, Shopify says you must have added all three authorities it needs: letsencrypt.org, pki.goog and ssl.com. A CAA record that lists only some other company can block Shopify's certificate. If you have no CAA records, there is nothing to do here.

Step 4: Check DNSSEC

Shopify says that on a third-party domain, a broken DNSSEC setup can stop the domain connecting, even when every other record is correct. The standard fix on its page is to turn DNSSEC off at your domain provider. The setting can be under DNS, Advanced DNS, Domain Security or Domain Settings, depending on the provider. If you cannot find it, ask the provider to turn it off. If you want to keep DNSSEC, Shopify says to work with your provider to correct it instead.

If the domain is managed by Shopify (for example you transferred it in from another provider), Shopify says DNSSEC is not supported and that you need to contact Shopify Support to have it removed.

Step 5: Look for a Cloudflare proxy

Shopify says it does not support the Cloudflare proxy or Orange-to-Orange (O2O). You can keep Cloudflare for DNS as long as every record that points to Shopify is set to "DNS only". Shopify's page says that if your Cloudflare settings already show "DNS only" and you still see the error, it may clear by itself within 24 hours, and after that you should contact Cloudflare's support team. If you are not on Cloudflare but think another proxy is involved, ask your domain host to review its proxy settings.

If it says "SSL unavailable"

Shopify describes this as the point where it cannot issue a certificate, and visitors may see "Your connection is unsecure". The causes it lists are incorrect DNS records, CAA records blocking certificate authorities, or DNSSEC being on. Go back through steps 2 to 5.

Shopify also lists two visitor-side items. If you are on Android 7.0 or lower, it says to upgrade the device, and if your browser is from before 2010, update it. So test on a different phone or browser before you decide the store is broken.

What to do if it is still stuck

If everything above checks out and the status is still pending or unavailable after 48 hours, Shopify's page says to contact Shopify Support. When you write, it helps to give your domain, which provider holds your DNS, and what you changed and when. Again, that is our suggestion rather than Shopify's list.

When to hire help

Get help if your provider's DNS screen is confusing, if email runs on the same domain (a wrong DNS change can interrupt it), or if the store is down and you are losing orders. Tidewell checks and corrects Shopify domain connections. We look at your DNS first, tell you what is wrong and agree a price before touching anything. Send us the store address and your domain provider's name: tell us what is happening. We never ask for your password.

Questions

Can I speed up the 48 hours?

Not that we know of. Fix any wrong record once and wait.

I turned off the Cloudflare proxy and it still shows an error.

Shopify says that if Cloudflare shows "DNS only", it may resolve within 24 hours. If not, contact Cloudflare's support.

The warning only shows on one device.

Try another phone or browser. Shopify lists Android 7.0 or lower and browsers from before 2010 as causes.

COMMON PROBLEMS

Start with the symptom.

Search cleanup

Spam pages are showing up

Unknown casino or spam pages need evidence, access review and careful cleanup.

Read the checklist →

Email delivery

Shopify emails go to spam

Check sender authentication, DNS and notification headers before changing records.

Read the checklist →

Merchant Center

Misrepresentation suspension

Audit store details, policies and product data before requesting another review.

Read the checklist →