Skip to main content
DNS & Infrastructure Updated

Shopify Domain Security: A Practical Baseline

A practical checklist for protecting the accounts, DNS records, and customer paths connected to a Shopify domain.

Official Setup Guides

For step-by-step instructions, check out these official guides from the source:

Protect the path a customer uses to reach the store

For a Shopify brand, domain security is more than one DNS record. A customer route can be changed through a registrar account, DNS provider, Shopify admin account, recovery inbox, redirect rule, app, or custom code. A good baseline makes those changes deliberate, visible, and recoverable.

Start with ownership and access

Maintain a short ownership record for every production domain: registrar, DNS provider, renewal owner, recovery inbox, Shopify owner, and people authorized to make changes. Then apply the same access standards to each account.

  • Use a password manager and unique credentials.
  • Require multi-factor authentication where the provider supports it.
  • Remove staff, agency, and contractor access when it is no longer needed.
  • Review recovery email addresses, phone numbers, and delegated administrator roles.
  • Enable appropriate registrar and transfer protections after confirming they match your operating process.

The recovery inbox is part of your domain-control plane. Protect it with the same care as the registrar account.

Keep DNS understandable

Document the expected DNS records and the service that owns each one. For a typical Shopify setup, the important records may include the Shopify connection, www handling, email-delivery records, verification TXT records, and intentional redirects.

Review these when you change a provider or launch a new service:

AreaQuestions to ask
Store routingDoes the primary domain and www resolve to the intended Shopify storefront?
EmailAre SPF, DKIM, DMARC, and MX records owned by the appropriate sending and receiving services?
RedirectsDoes each redirect lead customers to the correct product, regional store, or canonical domain?
SubdomainsDoes every DNS entry point to an active, owned service?
DNSSECIs it supported and configured correctly by the registrar and DNS provider?

Do not publish generic SPF or Shopify DNS values from a blog post. Use the current values and workflow provided by Shopify and the service that owns the record.

Review the storefront controls too

DNS can be correct while the customer path is altered inside the store. Review Shopify users, collaborator accounts, installed apps, theme code, custom scripts, and navigation redirects. Treat changes to checkout-adjacent scripts or redirects as production changes with an owner and a record.

Monitor what you do not control

You cannot own every lookalike domain. Watch for close registrations becoming active, copying your brand assets, redirecting to an unfamiliar payment destination, or appearing in suspicious customer email. Classify behavior before calling it abuse: a registration alone is not the same as an active impersonation attempt.

Respond to a suspected change

If a customer path, DNS record, account role, or registrar notice looks wrong, preserve the facts and contact the affected provider through its official security channel. Secure the recovery email and administrator accounts, then check for other unauthorized changes. Avoid promising customers a restoration time or naming an attacker before the evidence supports it.

See Responding to a Suspected Compromised Domain for a response sequence.

How Recon fits

Recon gives teams a three-surface view of inbox, checkout, and reputation signals that may need review. It does not manage DNS, lock a registrar account, or replace Shopify and provider security controls.

FAQ

Should we use a custom domain?

Use the domain that is right for your brand and customer communications. The important part is clear ownership, correct configuration, and an accountable operating process.

Does a domain lock protect everything?

No. It can reduce unauthorized transfer risk, but it does not secure the registrar inbox, DNS provider, Shopify admin, or third-party applications.

How often should we review the setup?

Review it after material provider, staff, DNS, email, or storefront changes, and on a regular schedule that fits your team’s operating model.

Want us to monitor this for you?

Get automated brand security monitoring for your Shopify store with Recon.

Install on Shopify