Shopify allows hijackers to claim subdomains

I'm writing this up as a warning to anyone with a Shopify account.


Let's say that you have a shop: You also have two CNAMEs:  and


The CNAMEs point to, which points to Shopify.


In your Shopify account, you link,  and


Later, you decide to create as a CNAME. You point it at your primary domain, which is very common. You have some plans for the future but don't start working with it right away. That's fine. Right?




Shopify currently allows anyone with a Shopify account to take over the subdomain without verification. For you to reclaim it, you will need to verify though!


People will typically connect their domains right away but Shopify should not allow users to claim a subdomain without any verification.


