webshop notifications being sent to non customers

Topic summary

A Shopify store owner is experiencing unauthorized customer account activation emails being sent to Gmail addresses (and possibly others) that are not in their database and have never interacted with the store.

Key Details:

  • Recipients receive “You’ve activated your customer account” notifications and are reporting them as spam
  • The affected users never visited the site or signed up for accounts
  • Issue began only after DMARC records were set up 10 days ago
  • Example emails contain Russian-like characters in the header (e.g., “Onebody Foundation (Australia) sales@onebody.me”)

Suspected Cause:
The store owner suspects a bot may have harvested Gmail addresses and is attempting to create fake accounts on their Shopify store.

Status: The issue remains unresolved with no clear solution identified.

Summarized with AI on November 12. AI used: claude-sonnet-4-5-20250929.

Somehow gmail addresses (and possibly others) are being sent notifications from my webstore. These addresses are not in my database, they are not previous or existing customers, and definitely not initiated by me.

The notification being sent out is ‘You’ve activated your customer account. Next time you shop with us, log in for faster checkout.’ Recipients are reporting this to me as spam. They had never been to my site, nor signed up for an account.

Maybe some bot has harvested Gmail addresses and is trying to set up fake accounts on Shopify stores.

Also note that this started happening only AFTER I set up and verified the DMARC records 10 days ago.

Email example has Russian-like characters in the header:
ср, 7 лют. 2024, 09:01 користувач Onebody Foundation (Australia) sales@onebody.me пише: