Official Setup Guides
For step-by-step instructions, check out these official guides from the source:
HTTPS protects the connection, not the brand by itself
TLS, often still called SSL, encrypts the connection between a browser and a website and lets the browser validate the certificate presented for that hostname. It is a baseline for a Shopify storefront, but a valid lock icon does not prove a store is legitimate, a message is authentic, or a checkout belongs to the brand a customer expects.
That distinction matters because lookalike sites can also use valid certificates. Customers should still check the domain and expected checkout path.
Shopify-managed certificates
Shopify provides certificates for eligible connected domains. Certificate availability depends on the domain connection and DNS configuration. Check the status in Shopify admin and follow Shopify’s current setup or troubleshooting guidance instead of relying on a generic issuance timetable.
When connecting or changing a custom domain:
- Use Shopify’s current DNS instructions for the domain type and connection method.
- Remove or correct conflicting records only after confirming what they are used for.
- Confirm the domain resolves to the intended storefront.
- Check the certificate status in Shopify admin and test the public URL in a browser.
DNS caches and domain validation can affect when a change becomes visible. If the status remains unresolved, use the official Shopify troubleshooting flow with the current DNS record details.
Common problems to investigate
| Symptom | Possible area to check |
|---|---|
| Certificate is pending or unavailable | Domain connection, DNS records, conflicting configuration, provider validation |
| Browser warning on a single asset | An insecure image, script, font, or third-party integration causing mixed content |
| Warning on one domain variation | www routing, redirect configuration, or a missing domain connection |
| Sudden unexpected certificate error | DNS changes, domain routing, provider status, or a possible access incident |
Do not paste a certificate error into a public ticket if it contains customer or account information. Capture the hostname, exact browser message, and current DNS state for the provider.
Keep the security model clear
The browser indicator tells a customer that the browser established a protected connection to the domain it reached. It does not tell them whether they reached the intended brand. Use clear domain communications, email authentication, controlled redirects, and checkout monitoring alongside HTTPS.
How Recon fits
Recon can surface certificate and reputation signals as part of the overall brand-trust view. It does not issue certificates, change Shopify domain settings, or determine whether a valid certificate belongs to an authorized brand.
FAQ
Do we need to buy a separate certificate for a typical Shopify store?
For an eligible Shopify-connected domain, Shopify provides certificate management. Check Shopify’s current documentation if your setup has unusual domain or enterprise requirements.
Does a valid lock icon mean a store is safe?
No. It means the connection to that domain is protected. A lookalike or fraudulent site can also present a valid certificate.
What is mixed content?
Mixed content occurs when a secure page attempts to load some resources over an insecure connection. Review the affected asset or integration and update it to use a secure URL.
Want us to monitor this for you?
Get automated brand security monitoring for your Shopify store with Recon.
Install on ShopifyRelated Articles
A Records and CNAME for Shopify
Learn the difference between A records and CNAME records and how to properly configure them for your Shopify store.
CAA Records for Shopify Domains
Learn how CAA records restrict which certificate authorities can issue SSL certificates for your Shopify domain.
DNS Propagation: Why Domain Changes Take Time
Understand why DNS changes don't happen instantly and what to expect when updating your Shopify domain settings.