Suped

Why did Shopify send DMARC setup emails to users who already have DMARC records?

Summary

Recently, many Shopify users, including those who already had properly configured DMARC records, received emails from Shopify urging them to set up DMARC. This situation led to confusion and, in some cases, panic among store owners. The core reason for this widespread notification appears to be an operational decision by Shopify rather than a specific issue with individual DMARC setups. The emails were likely part of a broad, proactive campaign to ensure that all Shopify merchants comply with the new email sender requirements set by major mailbox providers like Google and Yahoo. These requirements emphasize strong email authentication protocols, including DMARC, to combat spam and phishing. While seemingly redundant for already compliant users, this blanket approach simplifies the communication process for large platforms managing thousands of domains.

Suped DMARC monitor
Free forever, no credit card required
Get started for free
Trusted by teams securing millions of inboxes
Company logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logoCompany logo

What email marketers say

Email marketers have shared various perspectives on Shopify's blanket DMARC notification. Many understand the logistical challenges faced by large platforms in segmenting users based on complex technical configurations like DMARC records. However, there's also a clear sentiment of frustration regarding the unnecessary panic and confusion these general emails caused among clients, particularly those who were already compliant. This situation underscores the delicate balance between ensuring widespread compliance and maintaining a positive user experience.

Marketer view

Marketer from Email Geeks notes that Shopify likely sent the DMARC setup emails to all users, irrespective of their existing DMARC deployment status. This broad approach is common for large platforms when rolling out new compliance requirements.

10 Jan 2024 - Email Geeks

Marketer view

Marketer from Email Geeks explains that blanket emailing is a significantly simpler approach for large platforms than developing complex DMARC checking code for individual accounts. This efficiency often dictates communication strategies.

10 Jan 2024 - Email Geeks

What the experts say

Email deliverability experts generally agree that Shopify's decision to send blanket DMARC setup emails, while causing some user frustration, is a pragmatic approach for a platform of its size. They understand that verifying DMARC records across millions of domains in real-time for targeted messaging is a monumental technical challenge. Experts emphasize that the ultimate goal is to increase DMARC adoption rates in response to new industry requirements from major inbox providers like Google and Yahoo, which prioritize strong email authentication.

Expert view

Expert from Email Geeks notes that their own messaging strategy was designed to be generic, prompting users to confirm DMARC records and then proceed to other authentication steps if already compliant. This aims for broad engagement without overcomplicating instructions.

10 Jan 2024 - Email Geeks

Expert view

Expert from Email Geeks acknowledges that while the blanket approach is understandable from an operational standpoint, it inevitably leads to user panic, underscoring the inherent complexity of email authentication for the average user.

10 Jan 2024 - Email Geeks

What the documentation says

Official documentation and industry standards provide the technical framework for DMARC. These resources clarify that DMARC builds upon SPF and DKIM to offer domain owners a way to specify how receiving mail servers should handle unauthenticated emails from their domain. The recent emphasis by major mailbox providers on DMARC compliance means that platforms like Shopify are obligated to ensure their senders meet these heightened security requirements. Documentation often highlights the reporting capabilities of DMARC, which allow domain owners to gain insight into how their emails are being authenticated and handled globally.

Technical article

Documentation from DMARC.org clarifies that DMARC enables domain owners to protect their domain from unauthorized use, such as email spoofing and phishing, by specifying how recipient mail servers should handle unauthenticated emails purporting to be from their domain.

05 Apr 2023 - DMARC.org

Technical article

Documentation from Zoho Mail explains that a DMARC policy allows senders to indicate that their emails are protected by SPF and/or DKIM, and to tell receiving servers what to do if these authentication methods fail. This includes options for monitoring, quarantining, or rejecting emails.

10 Mar 2024 - Zoho Mail

14 resources

Start improving your email deliverability today

Get started