In this guide
A polished email cannot earn a click if the mailbox provider rejects it or places it in spam. Deliverability starts before the campaign: domain authentication, identity alignment, permission quality, sending history, complaint control, and the consistency of the traffic sent from the domain.
This guide explains the Shopify-specific setup and the operating practices around it. It is the technical foundation for the wider ecommerce email lifecycle system. It does not promise an inbox placement score, because mailbox providers make recipient-level decisions from many signals. It gives you a system for proving identity, reducing avoidable risk, and diagnosing change.
Fast summary
- SPF and DKIM authenticate sending identities; DMARC evaluates aligned authentication with the visible From domain.
- Use current Shopify-generated DNS records and inspect a real received header after verification.
- Roll out DMARC enforcement only after inventorying and aligning every legitimate sending source.
- Permission, complaint control, gradual volume, unsubscribe, and list hygiene drive reputation beyond DNS setup.
- Measure delivery and clicks by provider, and treat privacy-inflated opens cautiously.
Recommended platform
Some links are affiliate links. We may earn a commission at no extra cost to you. Disclosure
Separate acceptance, delivery, and inbox placement
Sent means the platform attempted the message. Delivered usually means the receiving server accepted it. Inbox placement describes whether the accepted message reached the primary inbox, another tab, or spam. Opens and clicks happen later and are influenced by tracking privacy. Do not use one number as a proxy for all four stages.
Authentication proves that sending systems are authorized to use a domain. Reputation reflects how mailbox providers and recipients respond to that traffic. Content and link quality can affect filtering. List permission and engagement affect complaints and future treatment. A deliverability audit must examine every layer.
Begin with the exact From domain and every service that sends as the brand: Shopify Messaging, Klaviyo, helpdesk, review platform, loyalty tool, transactional provider, and employee mail. A DMARC report often reveals forgotten services or unauthorized use that a single-platform dashboard cannot see.
| Layer | Question | Evidence |
|---|---|---|
| Authorization | Is this system allowed to send for the domain? | SPF and DKIM results |
| Alignment | Does an authenticated domain align with the visible From domain? | DMARC result and message headers |
| Acceptance | Did the receiving server accept the message? | Delivery logs, bounce codes, and deferrals |
| Placement | Where did the accepted message land? | Seed tests, provider tools, and recipient behavior |
| Reputation | How do providers and recipients treat this traffic over time? | Complaint, bounce, engagement, and domain or IP data |
| Conversion | Did the message create useful customer action? | Clicks, sessions, orders, replies, and unsubscribes |
Swipe horizontally to compare every column.
Diagnose the failed layer instead of calling every problem deliverability.
Understand SPF, DKIM, and DMARC as one system
SPF authorizes sending infrastructure for a return-path domain. DKIM adds a cryptographic signature associated with a signing domain. DMARC checks whether at least one passing SPF or DKIM domain aligns with the visible From domain and publishes a policy for failures. Authentication can pass while alignment fails, so the message headers matter more than a generic green badge.
Gmail's sender guidelines require SPF or DKIM for all senders to personal Gmail accounts and require SPF, DKIM, DMARC, and From-domain alignment for senders above its bulk threshold. Yahoo's sender guidance sets similar expectations and also calls for easy unsubscribe and low complaint rates.
A DMARC policy of p=none monitors without requesting quarantine or rejection. Enforcement should follow visibility. Collect aggregate reports, identify legitimate sources, align or remove them, then move policy gradually with expert review. Publishing a strict policy before authorizing every real sender can interrupt order, support, and marketing mail.
| Protocol | What it proves | What it does not prove |
|---|---|---|
| SPF | The sending source is authorized for the envelope domain | That the visible From domain is aligned or the content is wanted |
| DKIM | The signed message was authorized by the signing domain and was not altered in signed parts | That the signer matches the visible brand without alignment |
| DMARC | A passing SPF or DKIM identity aligns with the visible From domain | That the recipient wants the mail or it will reach the primary inbox |
| BIMI | Eligible brands may provide a governed logo signal after stronger authentication | Authentication, reputation, or guaranteed logo display |
Swipe horizontally to compare every column.
Authentication establishes domain identity; reputation and permission determine whether that identity is trusted.
Authenticate a third-party domain for Shopify sending
Shopify's current email setup documentation instructs merchants using a third-party domain to add Shopify-provided CNAME records for SPF and DKIM handling. Shopify notes that these CNAME records handle SPF for the sender address and that a separate SPF TXT record is not needed for that Shopify purpose.
Use the records generated in the store admin, not values copied from an old tutorial. DNS providers represent hostnames differently, and proxy settings can interfere with verification. Add each record exactly, wait for DNS propagation, then confirm authentication in Shopify and inspect a real delivered message's headers.
A store using Klaviyo or another provider needs that service's branded-sending-domain setup as well. Do not add multiple standalone SPF records at the same hostname; SPF evaluation expects one policy record. Follow each provider's supported CNAME or include design and stay within DNS lookup limits. If the architecture is complex, involve a deliverability or DNS specialist.
- 1
Inventory senders
List every platform that sends marketing, transactional, support, review, and employee email as the brand.
- 2
Choose visible From identities
Use domains and reply addresses customers recognize and that the team monitors.
- 3
Generate Shopify records
Use the current admin-provided CNAME values for the third-party domain.
- 4
Publish without proxying
Enter names and targets exactly as the DNS provider expects and avoid unsupported proxy behavior.
- 5
Verify in Shopify
Wait for propagation and confirm the platform recognizes the authenticated domain.
- 6
Inspect a real header
Send to test mailboxes and verify SPF, DKIM, DMARC, alignment, From, reply-to, and unsubscribe headers.
Roll out DMARC from observation to enforcement
Create a reporting destination that can process aggregate DMARC reports safely. Publish a valid policy for the organizational domain, initially with monitoring where appropriate. Review which sources pass SPF, DKIM, and alignment. Classify each source as legitimate, obsolete, misconfigured, forwarded, or unauthorized.
Fix legitimate senders by enabling DKIM, using an aligned return path where supported, or moving them to an appropriate subdomain. Remove obsolete services and credentials. Then increase policy carefully, monitoring order confirmations, password emails, support replies, review requests, and employee systems as well as campaigns.
DMARC syntax and organizational-domain behavior can be unforgiving. A malformed record, duplicate DMARC records, or an enforcement policy applied before source inventory can cause real delivery loss. Use a reputable validator and qualified help for complex multi-brand or multi-domain setups.
- 1
Observe
Publish a valid monitoring policy and collect aggregate reports at a managed destination.
- 2
Classify
Identify every legitimate and unauthorized source sending as the domain.
- 3
Align
Configure DKIM or SPF alignment for approved services and retire obsolete ones.
- 4
Test critical mail
Verify transactional, marketing, support, and employee streams across major providers.
- 5
Enforce gradually
Move toward quarantine or reject only after legitimate traffic is consistently aligned.
- 6
Monitor continuously
Treat new vendors and domain changes as authentication releases.
Watch out
Do not copy a p=reject record into DNS before inventorying every legitimate sender. Enforcement can block the store's own critical messages when alignment is incomplete.
Protect reputation with permission and controlled volume
Authentication is the entry requirement, not a license to send. Build the list through transparent forms, checkout consent, and customer expectations. Avoid purchased, scraped, or shared lists. Segment recent engaged subscribers and customers when warming a new domain or provider, then increase volume gradually while monitoring bounces, deferrals, complaints, and clicks.
Google and Yahoo both identify 0.3 percent as a complaint-rate boundary bulk senders should remain below, but a responsible program aims materially lower and reacts before reaching a published ceiling. Complaint data is incomplete across providers, so rising unsubscribes, declining clicks, and negative replies are useful early warnings.
Make unsubscribe easy. Bulk marketing messages should support the required one-click mechanism and include a visible body link. A preference center can offer frequency or topic choices, but it must also provide a complete marketing opt-out. Suppress hard bounces, complaints, and unsubscribes across all marketing sources.
- Warm with recently consented and behaviorally engaged recipients.
- Increase volume in controlled steps instead of importing the whole historical database.
- Exclude long-term unengaged profiles from regular campaigns and use a limited sunset process.
- Investigate acquisition sources that create unusual bounce, unsubscribe, or complaint rates.
- Keep transactional traffic useful and avoid hiding promotions inside operational messages.
- Support one-click unsubscribe and a visible, functioning body unsubscribe link.
Remove technical and content signals that reduce trust
Use accurate headers, a recognizable From name, a monitored reply path, and honest subjects. Avoid URL shorteners, mismatched tracking domains, attachment-heavy campaigns, image-only layouts, and links to pages with security or reputation problems. Keep the sending domain, tracking domain, and storefront relationship understandable.
Build responsive emails with real text, sensible image dimensions, alt text, and a useful plain-text part. Test authentication and links after template, ESP, or tracking-domain changes. A clean-looking visual preview does not reveal malformed headers, broken personalization, or redirect chains.
Separate streams when their purposes and reputational risks differ. Marketing, transactional, support, and employee mail can use governed subdomains and providers, provided customers still recognize the identity and DMARC alignment is correct. Separation is not a way to evade poor list practices; it limits operational blast radius and improves diagnosis.
| Failure | Why it matters | Check |
|---|---|---|
| Unaligned From domain | DMARC can fail despite authentication | Authentication-Results and From header |
| Shared or generic tracking domain | Links may look unrelated or inherit reputation | Rendered link destinations and provider configuration |
| Image-only creative | Meaning disappears with images blocked and accessibility suffers | Text-only and image-blocked rendering |
| Broken reply path | Customers cannot resolve questions and may complain | Send and answer a real reply |
| Redirect chains | More failure and filtering surface | Resolve every campaign link to its final secure destination |
| Mixed marketing in service mail | Can confuse purpose, consent, and user expectations | Subject, opening content, and primary purpose |
Swipe horizontally to compare every column.
Inspect the complete received message, not only the design canvas.
Monitor leading signals and diagnose by mailbox provider
Track delivery, hard and soft bounce categories, deferrals, complaints, unsubscribe, clicks, conversions, and domain-authentication status. Break trends down by mailbox provider, campaign versus flow, acquisition source, and recipient engagement. An issue concentrated at one provider suggests a different investigation from a decline across every destination.
Use Google Postmaster Tools when eligible, provider feedback loops where available, DMARC aggregate reports, and the ESP's deliverability dashboard. Klaviyo's deliverability monitoring guide notes that Apple privacy opens are included in reported opens, so do not define engagement from open data alone.
When performance falls, freeze unnecessary volume increases. Check recent DNS, domain, IP, template, tracking, list-import, and acquisition changes. Inspect SMTP responses and real message headers. Reduce sending to the most engaged audience while fixing the cause, then restore volume gradually. Do not keep resending the same message to prove the problem is real.
| Signal | Likely investigation | Immediate guardrail |
|---|---|---|
| Authentication failure | DNS, selector, alignment, or provider change | Pause affected stream until identity is restored |
| Hard bounces spike | Old import, form abuse, typo source, or invalid domain | Suppress failures and stop the source |
| Deferrals spike at one provider | Rate, reputation, or temporary provider response | Slow volume and read SMTP codes |
| Complaints rise | Permission, frequency, acquisition source, or misleading content | Narrow to recent engaged recipients |
| Opens change, clicks stable | Privacy or measurement shift | Use clicks and onsite behavior before changing strategy |
| Clicks fall across flows | Message relevance, links, rendering, or audience fatigue | Audit flow collisions and test received messages |
Swipe horizontally to compare every column.
Respond to the failed signal and provider pattern rather than changing every variable at once.
Frequently asked questions
For a third-party domain, Shopify provides CNAME records that connect the domain to Shopify's SPF and DKIM handling. The merchant still needs to publish those exact records, wait for propagation, verify the domain in Shopify, and test a received message.
