If you run a Shopify store and you haven’t published a DMARC record, this guide is for you. Most Shopify merchants don’t have one. The merchants who do, usually misconfigured it the first time. Both groups end up with the same outcome: scammers can send emails that look like they’re coming from your store, and your customers can’t tell the difference.
DMARC is the DNS record that fixes that. It tells inbox providers what to do with email that claims to be from your domain but doesn’t pass authentication. Set it correctly and impersonation drops sharply. Set it wrong and you’ll silently lose deliverability on your own marketing.
This guide is the 10-minute setup version for Shopify stores using common email tools. For deeper background on what DMARC actually is, see the DMARC knowledge base entry.
Why Shopify merchants are a target
A Shopify storefront is a high-trust environment for customers. When an order ships, customers expect emails from you. When a delivery is delayed, they read replies from you. When a return is processed, they trust the confirmation that lands in their inbox.
That trust is exactly what scammers exploit. The most common attacks on Shopify merchants are:
- Fake order confirmation emails sent from
youbrand.comoryour-brand.shop, pointing customers to a phishing checkout that captures payment info - Fake shipping update emails that link to a clone of your store hosted elsewhere
- Fake support replies that ask for “verification” payment information
Every one of these requires the attacker to send mail that appears to come from your domain. DMARC is what stops that.
The 10-minute setup
DMARC is a single DNS record. It looks like this:
v=DMARC1; p=none; rua=mailto:dmarc@yourstore.com
You publish that at _dmarc.yourstore.com and you’re done. That’s the entire technical step.
The reason it takes more than 30 seconds is that you need to pick the right policy and reporting destination, and you need to make sure SPF and DKIM are working first (DMARC builds on those).
Here’s the order of operations:
Step 1: Confirm SPF and DKIM are set up
DMARC checks whether an email passes either SPF or DKIM AND is “aligned” with the From: address. If neither is in place, every email you send will fail DMARC.
Before publishing DMARC, make sure:
- Your SPF record at
yourstore.comincludes every service that sends mail on your behalf (Shopify, Klaviyo, Mailchimp, Postmark, your transactional ESP, your support inbox like Help Scout or Gorgias). See the SPF records knowledge base entry for what to include. - DKIM is configured at each of those services and the public keys are published at the right CNAME records in your DNS. See DKIM records.
If you’re not sure, run a free email scan on your domain. It’ll tell you which of SPF, DKIM, and DMARC are missing or broken, and which sending services have valid keys.
Step 2: Pick a starting policy
DMARC has three policy levels:
p=none: Monitor only. Nothing gets blocked. Inbox providers send you reports about what’s authenticated and what isn’t.p=quarantine: Send unauthenticated mail to the spam folder.p=reject: Inbox providers reject unauthenticated mail outright.
Start with p=none. Always. Even if you’re a sophisticated team. Even if you’re sure your setup is correct. p=none is monitor-only — it tells you what would have been blocked without actually blocking anything. You’ll learn things about your sending setup from those reports that you didn’t know.
After 2–4 weeks of clean reports, move to p=quarantine. After another 4 weeks, move to p=reject. Don’t skip the middle step. See the DMARC policy levels guide for the staged rollout details.
Step 3: Set up a report inbox
DMARC reports are XML files that inbox providers send to a mailbox of your choice. The rua= tag in your record points to that mailbox.
You have three options:
- Use a dedicated mailbox at your domain (
dmarc@yourstore.com). Free. You’ll need to parse the XML yourself or paste it into a free viewer. - Use a DMARC reporting service like Postmark DMARC Digests, dmarcian, or Valimail. Most have free tiers under a small report volume.
- Use a brand protection tool that includes DMARC monitoring, like Recon.
For a merchant doing under $5M/year, a free DMARC reporting service is usually the right starting point. Once volume grows, the unified view inside Recon (alongside clone detection, lookalike domains, and SSL/header checks) becomes more useful than another tab.
Step 4: Publish the record
Log into your DNS provider (Cloudflare, GoDaddy, Namecheap, etc.) and create a TXT record:
- Host/Name:
_dmarc - Type: TXT
- Value:
v=DMARC1; p=none; rua=mailto:dmarc@yourstore.com; pct=100
The pct=100 tag means the policy applies to 100% of mail. You can dial this down during a staged rollout (e.g., pct=25 quarantines only a quarter of failing mail) but for p=none it doesn’t matter.
Save the record. DNS propagation usually takes minutes; allow up to 24 hours.
Step 5: Verify it’s published
Open a terminal and run:
dig TXT _dmarc.yourstore.com +short
You should see your DMARC string returned. If you get nothing back, the record didn’t publish correctly. Check the host field — some DNS providers require the bare _dmarc and some want the fully qualified _dmarc.yourstore.com.
You can also use Google’s Check MX record tool or just re-run Recon’s free scan, which checks DMARC presence and parses your policy.
How DMARC interacts with the Shopify stack
This is where most setup tutorials fall short. Shopify merchants don’t send mail from one place — they send from five or six. Each one needs to be aligned for DMARC to work cleanly.
Shopify’s transactional emails
By default, Shopify sends order confirmations and other transactional emails from noreply@shopify-stores.io or similar Shopify-owned addresses. Those emails are technically not from your domain, so they don’t affect DMARC at all.
If you’ve configured a custom sender domain in Shopify Admin → Settings → Notifications, then Shopify needs to be in your SPF record and DKIM needs to be set up on Shopify’s side. Shopify provides DKIM keys you publish as CNAMEs in your DNS.
Klaviyo
Klaviyo sends from your domain once you complete their dedicated-sender setup. You publish DKIM CNAMEs (Klaviyo generates the values), and you add Klaviyo to your SPF record.
The SPF include for Klaviyo is include:_spf.klaviyo.com.
Mailchimp
Mailchimp uses authenticated domain setup. You add a DKIM key as a CNAME record and include include:servers.mcsv.net in your SPF.
Postmark, SendGrid, and other transactional ESPs
Each generates DKIM CNAMEs and provides an SPF include string. Add them as you would Klaviyo or Mailchimp.
Support tools (Gorgias, Help Scout, Zendesk, Front)
If your support team sends replies from support@yourstore.com, those messages need to pass DMARC too. Each support tool has its own DKIM/SPF setup; don’t skip this. Customer-facing emails that fail DMARC are a slow leak that erodes deliverability.
Verifying DMARC is actually catching impersonation
Publishing a record is not the same as enforcing it. Until you reach p=quarantine or p=reject, DMARC is purely informational.
The right way to verify enforcement:
- Read your DMARC reports. Look at the “aligned” pass rate across all your sending sources. Anything below 95% means something is unauthenticated.
- Look at the source IPs. If you see senders you don’t recognize, that’s either a legitimate service you forgot about (sometimes a CRM or a billing tool sends mail too) or an impersonation attempt.
- Move to
p=quarantineonce your pass rate is consistently above 98%. - Test with mail-tester.com. Send a test message from each of your sending services. The tool grades alignment.
Common DMARC mistakes Shopify merchants make
- Starting at
p=reject. Don’t. You will block legitimate mail from a service you forgot to authenticate. Usep=nonefirst. - Forgetting about subdomains. A DMARC record at
yourstore.comdoesn’t apply tomail.yourstore.comunless you setsp=(subdomain policy). For most merchants, setsp=noneinitially. - Pointing reports to a mailbox that doesn’t exist. If
dmarc@yourstore.combounces, you’ll never see any reports. - Ignoring the alignment requirement. DMARC requires SPF or DKIM to pass AND the authenticating domain to align with the From: address. You can pass SPF and still fail DMARC if the SPF-authenticated domain doesn’t match your From: domain.
- Set-and-forget. Email-sending stacks change. A new ESP, a new CRM, a new fulfillment partner that sends shipping notifications — each one is a new authentication surface. Check your DMARC reports at least monthly.
Where DMARC fits in the bigger brand protection picture
DMARC stops email impersonation. It doesn’t stop a clone of your storefront from being hosted on yourbrand-sale.shop. It doesn’t catch a lookalike domain registered against your brand. It doesn’t generate a takedown notice when someone copies your product photography.
But it’s the cheapest, fastest brand protection move a Shopify merchant can make. It takes 10 minutes, costs nothing, and closes the most common attack vector against ecommerce brands.
Once DMARC is in place, the next step is monitoring the rest of your brand surface — copied storefronts, lookalike domains, phishing pages targeting your customers. That’s what Recon handles.
Run a free scan of your Shopify store and Recon will check DMARC, SPF, DKIM, and the dozen other domain-trust signals that determine whether a scammer can credibly impersonate you. Free in the Shopify App Store, no security team required.
Recon detects this automatically. Install free on Shopify →
← All posts