Official Setup Guides
For step-by-step instructions, check out these official guides from the source:
Protect the path a customer uses to reach the store
For a Shopify brand, domain security is more than one DNS record. A customer route can be changed through a registrar account, DNS provider, Shopify admin account, recovery inbox, redirect rule, app, or custom code. A good baseline makes those changes deliberate, visible, and recoverable.
Start with ownership and access
Maintain a short ownership record for every production domain: registrar, DNS provider, renewal owner, recovery inbox, Shopify owner, and people authorized to make changes. Then apply the same access standards to each account.
- Use a password manager and unique credentials.
- Require multi-factor authentication where the provider supports it.
- Remove staff, agency, and contractor access when it is no longer needed.
- Review recovery email addresses, phone numbers, and delegated administrator roles.
- Enable appropriate registrar and transfer protections after confirming they match your operating process.
The recovery inbox is part of your domain-control plane. Protect it with the same care as the registrar account.
Keep DNS understandable
Document the expected DNS records and the service that owns each one. For a typical Shopify setup, the important records may include the Shopify connection, www handling, email-delivery records, verification TXT records, and intentional redirects.
Review these when you change a provider or launch a new service:
| Area | Questions to ask |
|---|---|
| Store routing | Does the primary domain and www resolve to the intended Shopify storefront? |
| Are SPF, DKIM, DMARC, and MX records owned by the appropriate sending and receiving services? | |
| Redirects | Does each redirect lead customers to the correct product, regional store, or canonical domain? |
| Subdomains | Does every DNS entry point to an active, owned service? |
| DNSSEC | Is it supported and configured correctly by the registrar and DNS provider? |
Do not publish generic SPF or Shopify DNS values from a blog post. Use the current values and workflow provided by Shopify and the service that owns the record.
Review the storefront controls too
DNS can be correct while the customer path is altered inside the store. Review Shopify users, collaborator accounts, installed apps, theme code, custom scripts, and navigation redirects. Treat changes to checkout-adjacent scripts or redirects as production changes with an owner and a record.
Monitor what you do not control
You cannot own every lookalike domain. Watch for close registrations becoming active, copying your brand assets, redirecting to an unfamiliar payment destination, or appearing in suspicious customer email. Classify behavior before calling it abuse: a registration alone is not the same as an active impersonation attempt.
Respond to a suspected change
If a customer path, DNS record, account role, or registrar notice looks wrong, preserve the facts and contact the affected provider through its official security channel. Secure the recovery email and administrator accounts, then check for other unauthorized changes. Avoid promising customers a restoration time or naming an attacker before the evidence supports it.
See Responding to a Suspected Compromised Domain for a response sequence.
How Recon fits
Recon gives teams a three-surface view of inbox, checkout, and reputation signals that may need review. It does not manage DNS, lock a registrar account, or replace Shopify and provider security controls.
FAQ
Should we use a custom domain?
Use the domain that is right for your brand and customer communications. The important part is clear ownership, correct configuration, and an accountable operating process.
Does a domain lock protect everything?
No. It can reduce unauthorized transfer risk, but it does not secure the registrar inbox, DNS provider, Shopify admin, or third-party applications.
How often should we review the setup?
Review it after material provider, staff, DNS, email, or storefront changes, and on a regular schedule that fits your team’s operating model.
Want us to monitor this for you?
Get automated brand security monitoring for your Shopify store with Recon.
Install on ShopifyRelated Articles
A Records and CNAME for Shopify
Learn the difference between A records and CNAME records and how to properly configure them for your Shopify store.
CAA Records for Shopify Domains
Learn how CAA records restrict which certificate authorities can issue SSL certificates for your Shopify domain.
DNS Propagation: Why Domain Changes Take Time
Understand why DNS changes don't happen instantly and what to expect when updating your Shopify domain settings.