Search cleanup
Spam pages are showing up
Unknown casino or spam pages need evidence, access review and careful cleanup.
Read the checklist →SHOPIFY DOMAINS
Short answer: after you connect a domain, Shopify says it can take up to 48 hours for the TLS certificate to be issued, and an "SSL pending" or "TLS pending" status shows in your admin during that time. If it has been less than 48 hours, check your DNS records are right and wait. If it has been longer, or the status says "SSL unavailable", the cause is usually a setting at your domain provider: a wrong record, a CAA record that blocks certificate authorities, DNSSEC, or a proxy.
SSL and TLS are used interchangeably here. They mean the certificate that gives your store the padlock.
For the pending status, Shopify's advice is to wait 48 hours for DNS propagation and certificate provisioning. If you connected the domain yesterday, do not keep changing records every hour. Fix what is wrong once, then leave it. (Constantly editing records is our own advice, not something Shopify's page says, but it makes it hard to tell what worked.)
Log in to the company where you bought the domain (not Shopify, unless you bought it there) and open the DNS settings. Shopify needs three records:
Copy the exact values from your own Shopify admin, where you connect the domain, or from Shopify's current domain help page. Do not copy them from a blog post or from this page. Shopify's values can change, and one wrong digit is enough to stop the domain connecting.
Shopify's page also covers a few record problems on their own. Make sure you do not have a wildcard record (*.yourdomain.com) pointing to Shopify. Shopify says it is not supported and can interfere with your site, and to set records for each specific subdomain instead. If the admin says it cannot fetch a record, Shopify's advice is to check your DNS settings, wait up to 48 hours, and contact Support if it persists.
CAA records say which companies may issue certificates for your domain. If you use them, Shopify says you must have added all three authorities it needs: letsencrypt.org, pki.goog and ssl.com. A CAA record that lists only some other company can block Shopify's certificate. If you have no CAA records, there is nothing to do here.
Shopify says that on a third-party domain, a broken DNSSEC setup can stop the domain connecting, even when every other record is correct. The standard fix on its page is to turn DNSSEC off at your domain provider. The setting can be under DNS, Advanced DNS, Domain Security or Domain Settings, depending on the provider. If you cannot find it, ask the provider to turn it off. If you want to keep DNSSEC, Shopify says to work with your provider to correct it instead.
If the domain is managed by Shopify (for example you transferred it in from another provider), Shopify says DNSSEC is not supported and that you need to contact Shopify Support to have it removed.
Shopify says it does not support the Cloudflare proxy or Orange-to-Orange (O2O). You can keep Cloudflare for DNS as long as every record that points to Shopify is set to "DNS only". Shopify's page says that if your Cloudflare settings already show "DNS only" and you still see the error, it may clear by itself within 24 hours, and after that you should contact Cloudflare's support team. If you are not on Cloudflare but think another proxy is involved, ask your domain host to review its proxy settings.
Shopify describes this as the point where it cannot issue a certificate, and visitors may see "Your connection is unsecure". The causes it lists are incorrect DNS records, CAA records blocking certificate authorities, or DNSSEC being on. Go back through steps 2 to 5.
Shopify also lists two visitor-side items. If you are on Android 7.0 or lower, it says to upgrade the device, and if your browser is from before 2010, update it. So test on a different phone or browser before you decide the store is broken.
If everything above checks out and the status is still pending or unavailable after 48 hours, Shopify's page says to contact Shopify Support. When you write, it helps to give your domain, which provider holds your DNS, and what you changed and when. Again, that is our suggestion rather than Shopify's list.
Get help if your provider's DNS screen is confusing, if email runs on the same domain (a wrong DNS change can interrupt it), or if the store is down and you are losing orders. Tidewell checks and corrects Shopify domain connections. We look at your DNS first, tell you what is wrong and agree a price before touching anything. Send us the store address and your domain provider's name: tell us what is happening. We never ask for your password.
Not that we know of. Fix any wrong record once and wait.
Shopify says that if Cloudflare shows "DNS only", it may resolve within 24 hours. If not, contact Cloudflare's support.
Try another phone or browser. Shopify lists Android 7.0 or lower and browsers from before 2010 as causes.
COMMON PROBLEMS
Search cleanup
Unknown casino or spam pages need evidence, access review and careful cleanup.
Read the checklist →Email delivery
Check sender authentication, DNS and notification headers before changing records.
Read the checklist →Merchant Center
Audit store details, policies and product data before requesting another review.
Read the checklist →