Multiple Shopify merchants are experiencing Chrome phishing warnings when customers redirect from their custom domains to Shopify checkout URLs (domain.com → domain-com.myshopify.com).
Key Details:
Chrome displays “Did you mean [domain].com?” warnings, suggesting the checkout URL looks suspicious
Affects both standard Shopify API implementations and Hydrogen storefronts
Issue appears suddenly and wasn’t occurring previously
Warning does NOT appear in Chrome’s incognito mode
At least 5 Shopify Plus stores confirmed affected
Root Cause Identified:
One user traced the issue to Chrome’s lookalike domain security feature (chromium.googlesource.com documentation referenced).
Business Impact:
Merchants describe this as a “terrible situation” that disrupts checkout flow and potentially damages customer trust. The discussion remains unresolved, with users seeking help and expressing concern that Shopify Plus may not be aware of the severity affecting their entire merchant base.
Summarized with AI on November 13.
AI used: claude-sonnet-4-5-20250929.
We encounter the same issue on all our 5 shops and Shopify Plus seems to not be conscient how the problem will be massive for all Shopify shops if they don’t do anything.