- Francesco Guiducci, Ingegneria web design, Legge 132/2025, phishing 2026, protezione dati, shopify help, sicurezza shopify, spam e-commerce
- Francesco Guiducci
Shopify Phishing: How to Check Suspicious Emails and Protect Your Account

Direct answer: if you receive an urgent message that appears to come from Shopify, do not decide based on graphics or tone. Check the sender and URLs, avoid providing credentials or authentication codes and, if you are unsure, contact Shopify through official channels. Shopify publishes specific guidance on phishing, vishing and smishing.
Signals that require attention
According to the Shopify Help Center, common warning signs include unexpected emails from free email services, requests for personal data, urgent or threatening language and links to unfamiliar websites. None of these elements, taken alone, mathematically proves that a message is fraudulent: the context still needs to be verified.
How to verify an email that appears to come from Shopify
Shopify lists official communication domains including @shopify.com, @email.shopify.com, @em.shopify.com and, for specific Bill Pay communications, @shopify-billpay.melio.com. Shopify may also use trusted delivery services and some legitimate links can include the shopifysvc.com domain.
For that reason I do not use a simplistic rule such as “if it is not from one specific domain, it is phishing”. If the message remains doubtful, the correct verification is to contact Shopify Support directly through official channels.
What not to provide through a suspicious message
Do not enter passwords, two-step authentication codes, banking information or other sensitive data on a page reached from a link whose origin you have not verified. An attack may also ask you to download a file, open an attachment or reply directly with personal information.
If you already clicked or shared information
Shopify's guidance recommends acting immediately: change the account password, enable two-step authentication if it is not already enabled and contact Shopify Support to check for unauthorized access. You can also review devices with recent account access and sign out those you do not recognize.
Two-step authentication and passkeys
Shopify recommends secure sign-in methods because a password alone does not protect the account if it is stolen. Options include two-step authentication and passkeys. Passkeys can also reduce the risk of entering a password on a phishing page.
If several people access the store, each user should have their own account and the permissions needed for their work, rather than sharing credentials.
How to report a phishing attempt
Shopify provides the address phishing@shopify.com for forwarding phishing messages received. This helps Shopify collect information about attacks targeting merchants.
My scope
I’m Francesco Guiducci, a freelance Shopify specialist and Shopify app developer. When I work on the operational security of a store, I focus on configuration, permissions, theme, apps and technical checks; I do not present these activities as a guarantee against every future attack.
Main source: Shopify Help Center: phishing, vishing and smishing.
Updated September 3, 2026.

