Before your next newsletter, confirm your Sender email in Shopify admin, then check that your sending domain has the CNAME records Shopify provides for SPF and DKIM, plus a DMARC record. If those records are missing, Shopify rewrites your sender address to store+123@shopifyemail.com. Authentication supports deliverability; it does not guarantee inbox placement.
What Shopify actually controls, and what your DNS provider controls
Shopify separates two addresses. Your Store email is the address you signed up with, listed in Settings > General, and it receives exported product, order or customer files. Your Sender email is the customer-facing address in Settings > Notifications: it appears as the From address on order confirmations, automatic notifications and marketing emails, and it receives contact form submissions. (Official source)
Shopify can show you the authentication records and, for domains bought through Shopify, configure them automatically. For third-party domains hosted on Cloudflare, GoDaddy or IONOS, Shopify can also configure DNS records automatically. For any other third-party domain, you add the records yourself at your DNS provider. That split is the source of most pre-newsletter surprises: the admin looks correct while the DNS zone is incomplete.
Pre-send diagnostic: five checks before you schedule
Run this in order. It takes about fifteen minutes if you already have DNS access.
- Confirm the Sender email. In Shopify admin, go to Settings > Notifications and note the exact address. The domain after the @ is the one that must be authenticated. If your sender is info@johns-apparel.com, you authenticate johns-apparel.com.
- Confirm the store is on an active paid plan. Adding CNAME records is not possible for client transfer stores, dev stores, or stores on the Pause and Build plan. (Official source)
- Open your DNS zone. Log in where the domain's nameservers point, not necessarily where you bought the domain. If you are unsure who controls the account, work through the checks in Who Owns Your Domain Name? A Ten-Minute Check before touching records.
- Compare records. In Shopify admin under Settings > Notifications, view the CNAME records Shopify provides. At your DNS provider, confirm each host and value matches exactly. Do not add IP addresses; the CNAME records are sufficient for authentication.
- Check DMARC. Add a DMARC record at your DNS provider. Shopify's guidance is to add a DMARC policy so messages reach customers, and Gmail and Yahoo require domain authentication plus a DMARC record to send from a branded address. (Official source)
Do you need a separate SPF TXT record?
No. The CNAME records added during domain authentication handle SPF automatically for your sender email address. You do not need to add a separate SPF TXT record for this purpose. (Official source)
This is a common mistake: teams add both the CNAME records and a hand-written SPF TXT record, then create conflicts. If you already have an SPF record for other sending services, treat it as a separate decision and avoid duplicating what the CNAME already covers.
What happens if the records are missing or removed?
If authentication records are not configured, your sender email is rewritten to store+123@shopifyemail.com, where the number string is unique to your store. This meets minimum requirements so you can keep sending without interruption, but your customers see a Shopify address rather than your brand. (Official source)
Removing CNAME records after setup can cause deliverability issues, including bounces. Shopify Email then resets your sender address to store+123@shopifyemail.com until the records are restored at your third-party domain manager. The records remain available again in your admin under Settings > Notifications. (Official source)
Example: a UK shop preparing a seasonal newsletter
Hypothetical example, figures illustrative only. A UK retailer sends from hello@example-store.co.uk through a domain registered with one provider but whose nameservers point to another. The admin shows the Sender email correctly, so the team assumes everything is ready. Before a seasonal newsletter, they check the DNS zone at the nameserver provider and find the CNAME records were never added. They add them, add a DMARC record, wait for propagation, and send a test to a few internal addresses. The sender address stays branded instead of being rewritten. No deliverability outcome is guaranteed by this step; it removes one known cause of rewriting and bounces.
Decision table: what to do in each situation
| Situation | Action before sending |
|---|---|
| Domain bought through Shopify | Authentication is set up automatically; verify the Sender email and that a DMARC record exists. |
| Third-party domain on Cloudflare, GoDaddy or IONOS | Shopify can configure DNS records automatically; confirm the records appear in the zone. |
| Third-party domain elsewhere | Add the CNAME records from Settings > Notifications yourself, plus a DMARC record. |
| Store on Pause and Build, dev or client transfer | CNAME records cannot be added; resolve plan status first. |
| Records were removed after setup | Restore them at the DNS provider; the sender resets to store+123@shopifyemail.com until then. |
How to verify without guessing
After adding records, wait for DNS propagation, then send a test newsletter to addresses you control and inspect the raw headers. Look for the From address matching your Sender email and for authentication results referencing your domain. If the From address shows store+123@shopifyemail.com, the records are not being read as expected: recheck host names, values and the DNS zone where nameservers point. If you are also changing site structure around the same time, keep DNS and redirect work separate so email changes are not mixed with URL changes.
Mistakes that break branded sending
- Editing records at the registrar when nameservers point elsewhere.
- Adding IP addresses instead of the provided CNAME records.
- Adding a separate SPF TXT record that duplicates what the CNAME handles.
- Assuming a correct Sender email in admin means DNS is complete.
- Removing records during a cleanup and losing the branded sender.
- Treating authentication as a spam guarantee. It supports deliverability; content, list quality and engagement still matter.
Follow-up questions
Can I send my newsletter before DNS changes propagate?
You can send, but your sender may be rewritten to store+123@shopifyemail.com until the records are live. If a branded From address matters for this campaign, wait and test first.
Does authentication guarantee my emails reach the inbox?
No. Authentication addresses identity and policy requirements. Inbox placement also depends on recipient engagement, list hygiene and message content, which authentication does not control.


