TruboRankAI AI Visibility Infrastructure
AI Visibility Guide

Fix a Shopify SSL Certificate Stuck on Pending

Shopify SSL Pending can be a normal provisioning state after a DNS change, but it becomes a troubleshooting signal when the public records or certificate permissions do not match Shopify’s current requirements.

Quick Answer

Check Shopify Admin → Settings → Domains and compare the public DNS with the current Shopify requirements. Shopify presently documents one A record at 23.227.38.65, one AAAA at 2620:0127:f00f:5::, and a www CNAME to shops.myshopify.com, while some Shopify-generated A records can use another valid 23.227.38.x ending. Remove duplicates, allow Shopify’s documented CAA issuers, disable DNSSEC if Shopify flags it, and allow up to 48 hours after correct changes before escalating.

AI Summary

This guide separates normal Shopify TLS provisioning from persistent SSL failure. It checks domain status, exact current A, AAAA, and www CNAME values, duplicate routes, proxy incompatibility, CAA issuer restrictions, DNSSEC, propagation, browser symptoms, and the final store-discovery update after HTTPS works.

Quick Questions

How long can Shopify SSL stay pending?

Shopify says DNS propagation and TLS provisioning can take up to 48 hours after a change. A wrong record will remain wrong after that window.

Which DNS records does Shopify currently require?

The current general requirements include one A, one AAAA, and a www CNAME, but the Shopify-generated domain instructions and status should be treated as authoritative.

Can CAA stop Shopify SSL?

Yes. If CAA records exist but do not permit Shopify’s documented certificate authorities, certificate provisioning can fail.

When to wait and when to fix

Situation Decision
Correct records changed less than 48 hours ago Monitor propagation and Shopify status
A, AAAA, or CNAME differs publicly Correct the authoritative DNS zone
Multiple A or AAAA routes exist Remove conflicting website records
CAA blocks Shopify issuers Allow the documented authorities or remove the restriction
Everything is correct after 48 hours Collect evidence and contact Shopify Support
AI Bot Tracking

See which AI crawlers actually reach your website.

Track visits from GPTBot, ClaudeBot, PerplexityBot, search bots, and other discovery agents-then see which public pages attract their attention.

  • Monitor leading AI and search crawlers
  • Review which public pages receive visits
  • Connect crawler activity to your visibility work
Create Free Account Free account · No credit card required
Illustration of the TruboRankAI AI Bot Tracking dashboard with crawler visits and traffic trends. See your AI crawler activity Crawler visits show discovery, not guaranteed citations or traffic.

Main Explanation

Start with the status inside Shopify Admin. SSL Pending immediately after connecting or changing a domain can be expected, while Needs attention, SSL unavailable, or a state that remains after the documented window deserves investigation. Confirm that the store and domain are active and that the domain has not expired, been suspended, or remained partially connected to a previous ecommerce platform.

Compare the public DNS with Shopify’s current instructions, not with an old setup article. Shopify currently documents 23.227.38.65 for the A record, 2620:0127:f00f:5:: for AAAA, and shops.myshopify.com for the www CNAME. Shopify also notes that an automatically generated valid A can end differently, such as .68. If Admin displays a specific valid value, preserve it rather than mechanically replacing it.

Count the records as well as reading them. Shopify’s troubleshooting guide calls for one A and one AAAA record. An old A from another host or an unrelated AAAA can make different networks reach different infrastructure. The www hostname should resolve through the Shopify CNAME. Remove conflicting website routes only; keep MX, SPF, DKIM, and unrelated ownership TXT records required for email and services.

Verify the authoritative DNS provider. A domain registered at one company may use nameservers hosted elsewhere. Editing the registrar’s inactive zone does not change the public answer. Query NS, open the active DNS host, then verify A, AAAA, CNAME, and CAA publicly. If the authoritative response is already correct while recursive resolvers differ, propagation is a valid explanation.

Review proxying separately. Shopify’s current troubleshooting documentation warns about unsupported proxy configurations and describes DNS-only troubleshooting for Cloudflare-managed records. Do not assume that every Cloudflare integration is identical or follow a third-party workaround that conflicts with Shopify Admin. The store’s domain status and current official support path are the authority.

CAA controls which certificate authorities can issue for the domain. Shopify currently lists letsencrypt.org, pki.goog, and ssl.com. If no CAA record exists, there may be no restriction to fix. If CAA is present, ensure the documented issuers are permitted and remove a blocking semicolon policy. CAA applies through the DNS hierarchy, so inspect the effective policy rather than only one visible row in the provider UI.

Shopify also instructs users to deactivate DNSSEC when its domain troubleshooting identifies DNSSEC as the blocker. DNSSEC changes affect trust in the entire DNS zone, so confirm the warning and coordinate with the registrar rather than toggling it casually. After correcting DNS, CAA, or DNSSEC, wait for the published TTL and Shopify’s provisioning process before repeatedly disconnecting the domain.

Once HTTPS works, test the root and www versions, checkout transitions, theme assets, app embeds, and redirects in a private browser. Select one primary domain and update canonical URLs, sitemap submissions, analytics, email links, and Search Console. Then run a Shopify-focused TruboRankAI scan for crawl, product content, collection pages, AEO, GEO, and AI-discoverability issues. SSL recovery protects access; it does not by itself create rankings or sales.

Practical Steps

  • Read the exact domain and SSL status in Shopify Admin.
  • Verify the domain is active.
  • Compare public A, AAAA, and www CNAME records with current instructions.
  • Remove duplicate or legacy website routes.
  • Confirm the authoritative DNS provider and proxy status.
  • Review CAA issuer permissions and DNSSEC warnings.
  • Wait for the relevant TTL and provisioning window.
  • Test the secure store and audit its canonical production domain.
From Advice To Evidence

Stop guessing whether AI crawlers see your best pages.

Use crawler activity as an early discovery signal, identify pages that receive attention, and find important pages that may need a clearer path.

  • Monitor leading AI and search crawlers
  • Review which public pages receive visits
  • Connect crawler activity to your visibility work
Create Free Account Free account · No credit card required
Illustration of the TruboRankAI AI Bot Tracking dashboard with crawler visits and traffic trends. See your AI crawler activity Crawler visits show discovery, not guaranteed citations or traffic.
Make Visibility Measurable

Turn AI crawler visits into a repeatable visibility workflow.

Monitor discovery over time, compare activity across important pages, and use the evidence to decide what deserves attention next.

  • Monitor leading AI and search crawlers
  • Review which public pages receive visits
  • Connect crawler activity to your visibility work
Create Free Account Free account · No credit card required
Illustration of the TruboRankAI AI Bot Tracking dashboard with crawler visits and traffic trends. See your AI crawler activity Crawler visits show discovery, not guaranteed citations or traffic.

FAQ

Will reconnecting the domain make Shopify SSL faster?

Not necessarily. Reconnecting can restart work without fixing the underlying DNS, CAA, DNSSEC, or proxy problem. Correct the evidence first.

Is 23.227.38.68 a wrong Shopify A record?

Not automatically. Shopify says some automatically generated valid records can use a different final number. Follow the value and status shown in Shopify Admin.

Does SSL Pending stop Google from indexing the store?

An unavailable or insecure canonical host can disrupt crawling and visitors. After recovery, verify the final HTTPS URLs and Search Console status rather than assuming indexation.

Sources and methodology

The page converts Shopify’s current domain error states into an evidence-first order and was reviewed on 2026-08-16. Shopify Admin overrides general examples. Community symptoms informed the questions, while technical fixes come from official documentation. No SSL fix guarantees rankings, AI citations, or revenue.

These references support the changeable facts and study findings discussed above. Results depend on each source's sample, date, market, query set, and measurement method.

Related internal links