Shopify

Shopify certificate expired: TLS provisioning

Shopify issues TLS certificates automatically and blocks uploaded certificates. The 48 hour window, the CAA list, and the documented fixes.

Shopify certificate provisioning fails when required DNS records are wrong, DNSSEC remains active, or CAA omits one of the authorities Shopify lists. Check "Settings > Domains," correct the documented A, AAAA, and CNAME records, update CAA, deactivate DNSSEC, then wait for provisioning and verify the live certificate again.

Why Shopify does this

Shopify's docs: "TLS certificates are provided for free for all domains that are added to Shopify. A TLS certificate is issued automatically in the following circumstances" and "You can't use third-party SSL certificates with your Shopify store". The documented failure window: connecting a third-party domain "might take up to 48 hours for the TLS certificate to be issued", after which "a TLS or SSL unavailable message" means the DNS settings need attention. Their checklist: "Verify that your A record is 23.227.38.65, your AAAA record is 2620:0127:f00f:5:: and your CNAME record is shops.myshopify.com", "If you use CAA records, then verify that you have added all the required certification authorities" (letsencrypt.org, pki.goog, ssl.com), and "If you have DNSSEC activated for your domain, then deactivate it".

Check it right now

Before changing anything, confirm what a crawler actually sees. The check is free, takes one URL and needs no account.

Run the check

How to fix it

  1. In the Shopify admin, open Settings > Domains and check the certificate status for the domain.
  2. Verify the A record is 23.227.38.65, the AAAA record is 2620:0127:f00f:5::, and the CNAME record is shops.myshopify.com.
  3. If CAA records exist, confirm they include letsencrypt.org, pki.goog and ssl.com.
  4. If DNSSEC is active at the registrar, deactivate it as their troubleshooting instructs.
  5. Wait out the 48 hour provisioning window after any DNS change, then re-check.
  6. Re-check the certificate expiry with the free SSL and domain checker below.

Why it happens again

Every domain added to the store gets a certificate, and renewal is invisible while DNS stays pointed at Shopify. The failure follows a DNS change: a domain migrated to a new provider, a CAA record added for another vendor, or DNSSEC switched on at the registrar. The admin shows a TLS or SSL pending or unavailable message, which is easy to miss between orders.

stillindexed re-checks the URLs you give it every 30 minutes on Starter and alerts when a directive changes, at most 30 minutes after it does. It is a monitor rather than a crawler: it watches a list you choose and tells you when one of seven things changes. Card first, no trial, and a 30 day refund.

See what monitoring covers

Catching it next time

Fixing it once is the easy half. The setting that caused this can be changed again by anyone with access, and the page will keep returning 200 while it happens.

Other ways Shopify loses pages

An expired or expiring TLS certificate, on other platforms

Sources

Every claim about Shopify above is from their own documentation, read on 2026-08-30. Platforms change their settings; if one of these is out of date, their page wins and we would like to know.