If a Shopify email arrives from [email protected] instead of your branded address, check the sender domain’s authentication. Changing the display name or editing the email template will not repair missing domain records. Shopify requires its authentication CNAME records and a valid DMARC record for the branded sender path described in its current guidance.
Start with one received email and the address you expected it to use. This guide is for the person responsible for Shopify notifications or Shopify-sent marketing emails, working with whoever manages the domain. A message sent by another email platform needs that platform’s own authentication checks.
Identify the address and the service that sent it
Shopify separates Store email from Sender email. Store email, under Settings > General, receives account communications and data exports. Sender email, under Settings > Notifications, is the customer-facing address used for store notifications and marketing messages sent from the store. Updating the first field does not fix the second.
Write down the full expected sender address, the address actually shown in the received message, the message type and the sending service. A brand name above an email is only a display label. Expand the message details to inspect the address underneath it.
For an illustrative store using [email protected], the domain to investigate is cedar.example. If the storefront uses a different domain, do not copy records there simply because it appears in the browser address bar. Follow the domain associated with Sender email and the records Shopify generates for it. The .example address here is a placeholder, not a working store.
Find the missing part before changing DNS
DNS is the system that publishes your domain’s technical records. For this task, Shopify’s CNAME records connect the sender domain to its SPF and DKIM authentication. SPF authorizes a sending route; DKIM lets a receiving service check a message’s signature. DMARC supplies the domain’s policy for authentication and alignment with the visible sender.
The distinction matters when a setup screen looks complete. Shopify says domains bought through Shopify have SPF, DKIM and DMARC configured automatically. For supported third-party domains on Cloudflare, GoDaddy or IONOS, automatic authentication configures the CNAME records but does not configure DMARC. That remaining record needs a separate check.
Open Settings > Notifications and inspect Email domain authentication in the Sender email section. For manual setup, copy every CNAME record displayed into the DNS manager for that sender domain. Use the generated names and targets exactly; the number of records can vary. A screenshot from another store is not a source of values for yours.
Shopify explicitly says these CNAME records handle SPF automatically for this purpose. Do not add a separate SPF TXT record just to follow an older Shopify tutorial, and do not remove records used by other mail services. Ask the domain administrator to resolve any existing conflicting record rather than overwriting it without checking its owner.
Check DMARC without replacing a working policy
Have the domain administrator inspect the existing DMARC TXT record before adding anything. Shopify requires one valid DMARC record; multiple DMARC records can fail validation and cause the sender address to be rewritten. Also check the record name: some DNS managers append the domain automatically, so entering a full name can put the record in the wrong place.
Shopify documents v=DMARC1; p=none; as its default starting value. That is not a reason to replace an established policy used by the rest of the business. An existing policy may cover staff email, marketing platforms and other legitimate senders. Keep a copy of the current settings and have their owner assess the change across those services.
Shopify also flags strict alignment settings, adkim=s or aspf=s, as potential causes of authentication trouble. Its guidance recommends relaxed alignment for compatibility. If your domain deliberately uses strict settings, give the domain administrator this specific finding and ask for a reviewed solution. Do not silently weaken a shared policy to clear one Shopify warning.
For the example above, suppose all Shopify CNAME records are present but the domain has no DMARC record. The next task is to configure and verify that missing policy. Re-entering CNAME records, changing the sender’s display name or adding an unrelated SPF record does not address that gap.
Allow verification time, then inspect a fresh message
Shopify says authentication changes can take up to 48 hours. Record when the DNS change was saved, compare every name and target against the admin instructions, and check the authentication status again. If verification fails, inspect the entered records before assuming another wait will fix a typo.
- After the records verify, send a controlled internal test from the affected Shopify sending path. Record which notification or marketing test you used; a message from a different app proves a different route.
- Open the newly received message and inspect its actual From address. An email delivered before the change will not update itself.
- In Gmail on a computer, expand the details beneath the sender’s name. Google identifies the Mailed by and Signed by fields as authentication evidence. Record the domains shown instead of judging only the brand name or logo.
- Check that replying reaches the intended monitored inbox. Keep this reply test separate from authentication: successful outbound authentication does not prove the team can receive or answer replies.
A branded From address and authentication evidence establish what happened to that test message. They do not guarantee every future message will reach the inbox. If authentication checks pass but delivery remains poor, keep the original message and investigate the affected sending route, rejection details and recipient behavior separately.
Leave the next owner enough evidence
Save a short handover with the sender address, DNS provider, person responsible, record names changed, Shopify status, change time and test-message result. Avoid putting account credentials in the handover. Repeat the check after moving DNS hosting or changing the sender domain; Shopify warns that removing its authentication CNAME records can cause delivery problems and a fallback sender address.
If multiple emails arrive for one signup, that is a separate routing problem. Authentication determines whether a sending path can use the domain; it does not decide which welcome automation should run. Keep those investigations separate so a DNS repair does not become an unnecessary flow rebuild.
Questions that change the setup
Can I authenticate a Gmail address as my Shopify sender?
Why can I not add the authentication CNAME records in Shopify?
Does a forwarding address give me a branded mailbox?
Start with the one sender your customers are seeing today. Match it to the right service and domain, repair the specific missing record, then keep a fresh message as evidence. Inficial can help review the Shopify setup and coordinate the change with your domain administrator.
