Problem

You added your domain under Settings → Domains in Shopify, pasted the records into your registrar, and now the domain either shows your old site, throws a DNS error, or loads with a “Your connection is not private” warning. The your-store.myshopify.com URL works fine. The domain you actually paid for doesn’t. Shopify’s Verify connection button keeps failing and won’t tell you which of the records you touched is the wrong one.

Almost every stuck Shopify domain is one of three problems, and they break at three different layers: the records point the wrong way, the change hasn’t reached resolvers yet, or the certificate hasn’t issued. Check them in that order.

The apex and www need different records — and you can’t swap them

This is where most store owners go wrong, because the two names a customer might type look interchangeable and aren’t.

  • The apex — the bare example.com. This takes an A record pointing at Shopify’s IP, 23.227.38.65. One A record, one value. (If you have leftover A records from a previous host still sitting on the apex, delete them — a stray second A record pointing at your old server is why half your visitors land on the wrong site.)
  • www. This takes a CNAME pointing at shops.myshopify.com — not at your .myshopify.com store URL, and not at an IP.

You cannot flip these and give the apex a CNAME. The DNS spec forbids a CNAME from coexisting with other records at a name, and the zone apex is required to carry SOA and NS records — so a CNAME there is illegal. That’s the whole reason Shopify’s instructions look lopsided: a fixed IP in an A record for the root, a CNAME for www. Shopify prints both exact values on the domain’s page; take them from there rather than from a blog, in case they ever change.

Shopify can also connect some domains automatically if you bought them through a supported registrar — it edits the records for you through the registrar’s API. If that option is available and works, use it and skip the manual records entirely. What you must not do is both: half-automatic, half-manual leaves conflicting records.

“Verify connection” failing is usually a propagation answer

Once the records are right, Shopify still has to see them, and so does every resolver between your customer and your store. DNS changes don’t apply the instant you save — resolvers hold the previous answer until its TTL expires, which is why the domain can keep showing your old host for minutes to hours after you fixed everything.

Two traps live here:

  • You edited the wrong place. If your domain’s nameservers were long ago pointed at an external DNS provider (Cloudflare, your old host), the record you just changed at the registrar is a dead letter — nothing authoritative reads it. The records only count at whatever nameservers the delegation actually points to. (Not sure where that is? See Find Your Domain’s Nameservers and DNS Provider.)
  • You’re reading the panel, not reality. The registrar showing the right value in its editor doesn’t mean the world’s resolvers return it yet. A correct record mid-propagation looks identical to a missing one in Shopify’s Verify connection check.

Shopify re-checks on its own. If the records are genuinely right, this is a waiting game, not a fixing one.

The certificate issues itself — unless something blocks it

Once your domain resolves to Shopify, it requests a free TLS certificate automatically; you never generate or upload one. That can take up to 48 hours, and during the gap the browser shows “Your connection is not private” because there’s no valid certificate for your name yet. That warning on a freshly connected domain is almost always the certificate still provisioning — not a broken setup.

Two things keep a certificate from ever issuing, though, and they look the same as “still waiting”:

  • A CAA record that doesn’t allow the CA. If your domain has a CAA record, it’s an allowlist of which certificate authorities may issue for you. If it doesn’t name the CA Shopify uses (Let’s Encrypt), the CA is obligated to refuse, and your certificate silently never arrives. Either remove the CAA record or add an entry for letsencrypt.org.
  • A proxy sitting in front. A Cloudflare (or similar) record left on proxied / orange-cloud intercepts the connection, so Shopify’s issuance challenge hits the proxy instead of Shopify. Set the record to DNS-only while you connect the domain.

With both the apex and www resolving to Shopify, no hostile CAA, and no proxy in the way, the certificate lands — usually within an hour, occasionally up to the full 48.

Diagnose with DechoNet

  • DNS Lookup reads the A record on your apex and the CNAME on www straight off the authoritative nameservers, so you can confirm they actually point at 23.227.38.65 and shops.myshopify.com — and catch a stray old A record you forgot to delete. It also shows any CAA record that might be blocking the certificate.
  • Propagation Check shows whether resolvers around the world return the new records yet — the difference between “my setup is broken” and “I need to wait for the old TTL to expire.”
  • SSL Check confirms, once the domain resolves to Shopify, that a valid certificate is actually being served for both the apex and www — the step that turns off the browser warning.

Verification Checklist

  • Apex (example.com) has one A record pointing at 23.227.38.65 — no leftover A records from a previous host.
  • www has a CNAME to shops.myshopify.com (not your store’s .myshopify.com URL, not an IP).
  • You’re editing DNS at the provider the domain’s nameservers actually point to, not a registrar panel that’s no longer authoritative.
  • A propagation check shows resolvers returning the new records — if not, the records may be right and still mid-propagation.
  • No CAA record blocks the CA (remove it or allow letsencrypt.org), and no record is left proxied in front of Shopify.
  • After DNS is correct, an SSL check shows a valid certificate on both the apex and www (allow up to 48 hours for first issuance).

When to Escalate

  • If DNS resolves correctly to Shopify everywhere and Verify connection still fails after the old TTL has fully expired, remove and re-add the domain in Shopify to force a fresh check — a stale verification state, not a DNS problem.
  • If the certificate is still absent after 48 hours with correct DNS, no blocking CAA, and no proxy, it’s an issuance problem; contact Shopify support with the exact hostname rather than re-editing records that are already right.
  • If your DNS provider offers no A record option on the apex at all, you can’t host the bare domain on Shopify directly — move DNS to a provider that supports apex records, or serve from www and redirect the apex to it.

Check your own domain now

Free, no sign-up. Runs the exact check this guide describes and shows what to fix.