Why your Shopify emails say "via shopifyemail.com" and how to fix sender alignment

✍️ Mindaugas Bružas4 min readShopifyShopify EmailSender AlignmentDMARCDKIMSPFvia shopifyemail.comEmail DeliverabilityMailMedicShopify Apps
Why your Shopify emails say "via shopifyemail.com" and how to fix sender alignment

Open an order confirmation from your own store in Gmail. If the sender line reads yourstore.com via shopifyemail.com in grey, Gmail is telling recipients that the message was sent by a server your domain did not vouch for. It is a small label with a large effect: those messages are the first to be filtered, rate-limited or dropped when a mailbox provider is being cautious.

This post explains what the label means, why it matters more since the 2024 sender requirements from Google and Yahoo, and what to change at your domain provider.

What "via" means

Email has two "from" addresses. The visible one is orders@yourstore.com. The technical one, used for bounces and authentication, is set by the sending server, in this case Shopify's. When the two domains differ and your domain has not authorised Shopify's servers, Gmail shows "via" the technical domain.

Three records let your domain vouch for Shopify:

  • SPF lists which servers may send mail for your domain. Shopify's include is include:shops.shopify.com.
  • DKIM lets Shopify sign each message with a key published under your domain. Shopify gives you CNAME records to add; once they resolve, the signature is "aligned" with your domain.
  • DMARC tells receivers what to do when SPF or DKIM fail, and asks them to send you reports.

When DKIM is aligned, the "via" label disappears. When SPF, DKIM and DMARC all pass, your mail is treated as coming from you, not from a bulk sender.

Why it matters more since 2024

Google and Yahoo now require bulk senders (roughly, anyone sending 5,000+ messages a day, but the rules are applied more broadly in practice) to have SPF and DKIM, a DMARC policy, aligned domains and a one-click unsubscribe for marketing. Stores that skipped authentication saw open rates drop and "delayed" notices climb. Order confirmations are transactional and treated more leniently, but they share reputation with your marketing sends.

The fix, step by step

  1. Shopify admin → Settings → Notifications → Sender email. If it shows "unauthenticated", Shopify lists the DNS records it needs. Copy them.
  2. At your domain provider (not in Shopify, unless the domain is bought through Shopify), add the CNAME records for DKIM exactly as given. Add include:shops.shopify.com to your SPF record, keeping the existing includes for your other senders (Google Workspace, Klaviyo). One SPF record only; two SPF records make both invalid.
  3. Add a DMARC record if you have none: v=DMARC1; p=none; rua=mailto:dmarc@yourstore.com. Start with p=none to receive reports without blocking anything, then move to quarantine once reports show all legitimate senders are aligned.
  4. Wait for DNS, usually minutes, sometimes up to 48 hours. Send yourself a test order and check the sender line in Gmail.

Checking it without guessing

Each of those steps has a way to go wrong silently: a CNAME with a trailing dot missing, an SPF with eleven includes (the limit is ten lookups), a DMARC record on the wrong subdomain. Tools like MXToolbox check one record at a time and leave the interpretation to you.

MailMedic runs the whole set in one go from inside Shopify: SPF, DKIM, DMARC, MX and the sender alignment between your store's sender address and Shopify's servers. Each problem is explained in plain language with the exact record to add, worded for your DNS provider. It reads public DNS only and never changes anything, so there is nothing it can break. One domain is free; Pro at 1.99 USD per month re-checks weekly and alerts you when a record changes, which happens more often than you would think when several people have access to DNS.

Frequently asked questions

My domain was bought through Shopify. Do I still need this? Shopify-managed domains are usually authenticated automatically. Run the check anyway; it takes ten seconds and confirms it.

I use Klaviyo for marketing. Does that change anything? Klaviyo has its own DKIM records and its own alignment. Both Shopify and Klaviyo need to be authenticated, and both need to be in your single SPF record. MailMedic shows them side by side.

Will fixing alignment stop all spam-folder problems? It fixes the authentication part, which is the most common cause. List quality, complaint rate and content still matter for marketing mail.


MailMedic is built by MB „Liūto media" in Lithuania. All our Shopify apps are listed at liutoapps.com.

MB
Mindaugas Bružas

Founder of MB „Liūto media“ — building six focused Shopify apps: estimated delivery dates, shipping bars, product badges, email deliverability, theme cleanup and reorder reminders.

Built by the team behind six Shopify apps. See what we make →