Why Your Shopify Customers Never Get Their Login Code
A customer emails to say they cannot sign in. The code never came. You check your store, everything looks normal, you send a test to your own address and it arrives instantly. So you tell them to check spam and move on. Then it happens again the following week, and again, and eventually you realise you have no idea how many customers hit this and simply left. Here is how to find out which of four causes you actually have.
Why this is worse than it used to be
Under legacy customer accounts, a failed email meant a failed password reset. Irritating, but the customer could still sign in with the password they already had.
Customer accounts are passwordless. The one-time code is not a recovery path, it is the only path. If the email does not arrive, the customer cannot sign in at all, and there is nothing on your storefront to tell you it is happening. Every other kind of store breakage produces a symptom you can see. This one produces silence and a slow decline in returning customer revenue.
Cause one, your sender domain is not authenticated
This is the most common cause by a wide margin, and it usually starts with a reasonable decision. Somebody changed the sender address from the Shopify default to something branded like hello@yourbrand.com. Sensible for the customer experience, and it silently breaks deliverability unless the DNS is set up to match.
Mailbox providers check whether the domain in the from address has authorised the server doing the sending. Without that, Gmail, Outlook and Yahoo are entitled to junk the message or reject it outright, and increasingly they do.
In Shopify, go to Settings, then Notifications, and find the Sender email section, then Email domain authentication. Shopify provides CNAME records to add to your domain. Those records handle SPF and DKIM for your sender address, so you do not need to add a separate SPF TXT record for this purpose.
You also want a DMARC policy. The minimum Shopify asks for is v=DMARC1; p=none, which is a monitoring policy rather than an enforcing one and is a reasonable starting point.
Two useful shortcuts. If you bought your domain through Shopify, authentication is configured for you automatically. If your domain is on Cloudflare, GoDaddy or IONOS, Shopify can configure the records automatically as well. Otherwise you are adding them at your DNS provider by hand, and changes can take up to 48 hours to take effect, so do not judge the result the same afternoon.
Cause two, the sender address is not a real mailbox
Distinct from authentication and easy to miss. Shopify's own pre-upgrade checklist tells merchants to confirm the sender email address is current and accessible.
Stores accumulate addresses. Somebody set the sender to an address at an agency that no longer works with you, or to a personal address belonging to an employee who left, or to a mailbox that was never actually created. The messages go out, the bounces go somewhere nobody reads, and nobody notices.
Check that a human can open the inbox for whatever address is in that field, and that replies to it reach someone. This takes two minutes.
Cause three, shared sending reputation
This one is not your fault and you cannot fully fix it, so it is worth understanding rather than fighting.
Shopify sends notification email through shared infrastructure. Your messages leave the same systems as an enormous number of other stores, and the behaviour of those other senders affects how mailbox providers treat that infrastructure. A store doing something careless can influence filtering for everyone using the same path.
What authentication does is separate your domain's reputation from the crowd's. An authenticated domain with a DMARC record and a consistent sending history is judged on its own record rather than purely on the infrastructure it uses. That is precisely why cause one matters more than it sounds.
Cause four, the customer's own mail environment
Real, but check it last, because it is the explanation people jump to first and it is the least common.
Corporate mail filters are aggressive, particularly with B2B customers whose IT department blocks anything that looks transactional from an unfamiliar sender. Some customers genuinely do have full mailboxes or aggressive rules. And older customers sometimes do not have practical access to the email address they used at checkout, because it was created for one purchase years ago.
That last one is a real pattern in India, where a shopper who transacts entirely by phone and WhatsApp may treat email as something they never open.
How to diagnose it in twenty minutes
- Check Settings, Notifications for your sender address. Is it a real mailbox somebody can open?
- Check whether domain authentication is complete in the same screen. This is the single highest-value check on the list.
- Request a login code to a Gmail, an Outlook and a corporate address that you control. Testing only against your own work inbox proves very little.
- Look at where it lands. Inbox, promotions tab, spam, or nowhere at all. Each points somewhere different.
- Ask affected customers which provider they use. A pattern across one provider narrows it fast.
If codes arrive at Gmail and vanish at Outlook, that is an authentication and reputation problem, not a customer problem. If they arrive everywhere in the spam folder, same conclusion. If they arrive in the inbox everywhere and one customer still cannot see them, that is genuinely their mail environment.
What to do about the customers you already lost
Once the underlying problem is fixed, a short email to customers who have not signed in for a while is worth sending, telling them sign-in now uses a code sent to their email and to check spam once if it does not appear. Some of them stopped trying months ago and never told you.
Also give people a route that does not depend on email at all. If Shop Pay is active, customers can sign in with their Shop credentials and saved passkeys. Google and Facebook sign-in are also available. Those paths bypass the code entirely, and enabling them costs nothing.
Stop it happening again
Deliverability is not a job you finish. Two habits keep it working.
Set a DMARC reporting address so you receive the aggregate reports rather than sending them nowhere. They are unglamorous XML files and most people never look at them, but they are the only place you find out that something is sending mail as your domain, or that a provider has started rejecting you, before customers do.
And add a login test to whatever you check before a sale. Request a code to a Gmail and an Outlook address and confirm both land in the inbox. It takes two minutes and it is the difference between finding a problem in a quiet week and finding it on the morning of a campaign, when every returning customer you just emailed is trying to sign in at once.
Why do Shopify login codes go to spam?
Usually because the sender domain is not authenticated. If you changed the sender address to your own domain without adding Shopify's CNAME records and a DMARC policy, mailbox providers cannot verify the message is authorised and will filter it. Fixing that in Settings, Notifications resolves most cases, though DNS changes can take up to 48 hours.
Can customers sign in without an email code?
Yes, if you enable the alternatives. Customer accounts support Shop Pay sign-in with saved passkeys, and Google and Facebook social login, alongside the email code. Turning these on gives customers a path that does not depend on email delivery at all.
Does Shopify support SMS login codes?
No. The documented sign-in methods are the email one-time code, Shop Pay with passkeys, Google and Facebook social login, and on Shopify Plus a custom identity provider. Phone or SMS authentication is not among them.
How do I know how many customers this is affecting?
You cannot see failed sign-in attempts directly, which is what makes it dangerous. The proxy measures are your returning customer rate and support contacts mentioning login. If either moved after you switched to customer accounts, assume the number is larger than the complaints suggest, since most people do not write in, they just leave.
Will authenticating my domain fix everything?
It fixes the largest cause and improves every other email your store sends, including order confirmations. It will not help if the sender address is a mailbox nobody owns, and it cannot control an individual customer's corporate spam filter. Do it first, then re-measure.
Get your login delivery checked
Free check. Email hello@exactwhy.com with subject "Login codes" and your store URL. We check whether your sender domain is authenticated, whether your DMARC record exists, and where your codes actually land across the major providers. We respond within 4 hours. If your setup is clean, we will tell you and you can stop worrying about it.
Paid deliverability work, Rs 40,000 to Rs 1.5 lakh. Domain authentication, DMARC setup and monitoring, alternative sign-in paths enabled, and testing across providers so you know it is fixed rather than hoping.
Ongoing Shopify development, Rs 20,000 to Rs 50,000 a month. Including monitoring the notifications that keep your customers able to log in and buy again.
If you upgraded to customer accounts recently, our upgrade guide covers the rest of the checklist, and the architecture piece covers what to do if you need identity handled outside Shopify entirely.