Chrome domain phishing warning when redirecting to checkout

Topic summary

Multiple Shopify merchants are experiencing Chrome phishing warnings when customers redirect from their custom domains to Shopify checkout URLs (domain.comdomain-com.myshopify.com).

Key Details:

  • Chrome displays “Did you mean [domain].com?” warnings, suggesting the checkout URL looks suspicious
  • Affects both standard Shopify API implementations and Hydrogen storefronts
  • Issue appears suddenly and wasn’t occurring previously
  • Warning does NOT appear in Chrome’s incognito mode
  • At least 5 Shopify Plus stores confirmed affected

Root Cause Identified:
One user traced the issue to Chrome’s lookalike domain security feature (chromium.googlesource.com documentation referenced).

Business Impact:
Merchants describe this as a “terrible situation” that disrupts checkout flow and potentially damages customer trust. The discussion remains unresolved, with users seeking help and expressing concern that Shopify Plus may not be aware of the severity affecting their entire merchant base.

Summarized with AI on November 13. AI used: claude-sonnet-4-5-20250929.

We have a website that uses Shopify’s API and checkout.

Our domain is xxxx.com and the checkout domain is xxxx-com.myshopify.com

We’ve noticed today that our users are randomly getting this notice on chrome when going to the checkout:

Did you mean xxxx.com?
The site you just tried to visit looks fake. Attackers sometimes mimic sites by making small, hard-to-see changes to the URL.

This is a terrible situation for our business and it wasn’t happening before. Can you help us fix this?

Best, Valeria

1 Like

I’m getting this notification as well with my Shopify Hydrogen storefront. Chrome doesn’t throw a warning when in incognito mode.

Google Chrome

Version 120.0.6099.199 (Official Build) (x86_64)

We encounter the same issue on all our 5 shops and Shopify Plus seems to not be conscient how the problem will be massive for all Shopify shops if they don’t do anything.

We found why this problem occurs : https://chromium.googlesource.com/chromium/src/+/master/docs/security/lookalikes/lookalike-domains.md

Same problem here with Hydrogen storefront, when visiting the myshopify checkout url…