Should Shopify merchants use their main store domain for cold outreach?

Your store domain does more than host your storefront.
It sits behind order receipts, password resets, shipping updates, and support replies. When a customer needs help getting into their account, that email needs to arrive.
Cold outreach has a different job and a different risk. You’re writing to people who did not ask to hear from you. Some will ignore the message. Some may report it as spam. That can affect whether later messages from the same domain reach an inbox.
We bought a separate domain for our own cold outreach rather than sending from `lunalink.ai`.
The reason was simple. Our product domain carries email that people need: password resets, receipts, and normal business mail. We did not want cold outreach to share the same reputation risk.
Don’t send cold outreach from the domain customers depend on
Say your store is `cedarandclay.com`.
Customers may get messages from:
- `support@cedarandclay.com`
- `orders@cedarandclay.com`
- `hello@cedarandclay.com`
Those addresses are part of the customer experience. A delayed order receipt is frustrating. A password-reset email in spam can stop someone from getting into their account. A support reply that never arrives can turn a small issue into a chargeback or a lost customer.
Cold outreach is not the same as email marketing to subscribers.
Email marketing goes to people who opted in. They expect product news, offers, or restock notices. Cold outreach starts without that permission. Even if the message is relevant and carefully written, it has a higher chance of being unwanted.
Gmail says frequent spam reports can lower a domain’s reputation. Future mail from that domain is then more likely to be marked as spam. Gmail’s guidance also says that a spam rate above 0.3% removes eligibility for delivery support or mitigation.
That is enough reason to keep your main store domain out of the experiment.
A separate subdomain helps, but it is not full separation
Microsoft advises senders not to use their primary email domain for bulk email. Its example uses a custom subdomain for marketing, such as `m.contoso.com`, while transactional mail uses another subdomain, such as `t.contoso.com`.
For a store, that could look like this:
- `orders@store.com` for receipts and order updates
- `support@store.com` for customer help
- `deals@mail.store.com` for opted-in promotions
- `hello@outreach.store.com` for outreach
That setup makes the purpose of each stream clearer. It also lets you set up and monitor each sending setup separately.
But do not treat a subdomain as a complete reputation firewall.
Gmail counts its bulk-sender threshold across messages sent from the same primary domain. In other words, `outreach.store.com` and `store.com` are still connected for Gmail’s calculation of whether you send 5,000 or more messages per day to Gmail accounts.
That does not mean a subdomain has no value. It means the boundary is useful, not magic.
We chose a separate domain for our own cold outreach because we wanted a clearer boundary than a subdomain provides. That domain is for outreach only. Our main domain remains for the website, product mail, and the messages people expect from us.
A separate domain also makes the decision easier to maintain. If someone asks, “Can we send this cold campaign from the product address?” the answer is no. That address has another job.
Keep transactional, promotional, and outreach mail distinct
Gmail recommends separating different types of mail. Its examples use different `From:` addresses for receipts, promotions, and account notifications. Where possible, it also recommends using different IP addresses for different message types.
For a Shopify merchant, the useful part is the separation of purpose.
Start by making a short list of every kind of email your business sends:
- Order confirmations
- Shipping notifications
- Password resets and account notices
- Customer support replies
- Newsletter and campaign mail
- Supplier, wholesale, or partnership outreach
Then write down the sender address for each one.
You may find that everything currently comes from one address. That is common. It is also a reason to pause before adding cold outreach to the same setup.
A customer should be able to tell what an email is and why it arrived. Your sending setup should make that easier too.
Don’t use Shopify Email for a cold list
Shopify Email is for subscriber marketing, not ordinary cold outreach.
Shopify’s Email Services requirements list non-permission-based lists, purchased or rented lists, missing unsubscribe links, and failure to honor removal requests within 10 days as practices that may violate its requirements. Shopify can suspend or terminate access.
Shopify also says purchased subscriber lists can damage sender reputation, increase spam complaints, and result in mail being blocked. Its guidance is to send marketing email only to customers who opted in.
So keep the line clear:
- Use Shopify Email for customers and subscribers who gave permission.
- Do not upload a bought list into Shopify.
- Do not treat an old contact list as consent without checking how those addresses were collected.
- Do not send cold outreach from the address your customers use for orders and support.
If you decide to do outreach, use a tool and sending setup intended for that work. More importantly, keep the list small, relevant, and easy to leave.
Set up the basics before you send anything
The technical setup matters because inbox providers need to know that your domain authorizes the mail being sent.
For any domain or subdomain you use, check its DNS records before sending a real campaign:
- SPF says which mail servers may send for the domain.
- DKIM adds a signature to the message.
- DMARC tells receiving providers what to do when SPF or DKIM checks fail.
Shopify says branded sender addresses need SPF/DKIM authentication and a DMARC record for legitimate Shopify mail. The same habit is sensible for any sending domain: do not start sending until authentication is in place.
You can verify this in under a minute. Open the DNS settings for the domain you plan to send from. Search for records beginning with:
- `v=spf1`
- `v=DKIM1`
- `v=DMARC1`
If you cannot find them, stop and set them up with your email provider before sending.
Also send a test email to a Gmail address you control. Open the message menu and look for the authentication details. Gmail will show whether SPF and DKIM passed.
Unsubscribe needs to be more than a link in the footer
For large Gmail senders, Gmail’s requirements began in February 2024 and enforcement ramped up in November 2025. Senders reaching 5,000 or more messages per day to Gmail accounts must authenticate their mail, avoid unwanted or unsolicited mail, and make unsubscribing easy. Noncompliant messages can be temporarily or permanently rejected.
For marketing and promotional mail, Gmail requires one-click unsubscribe support through `List-Unsubscribe` headers, including an HTTPS URL. A `mailto:` link does not meet that requirement. Neither does an ordinary unsubscribe link only in the email body.
Even if your outreach volume is much lower, this is a good standard to use.
Your email tool should add the required headers. Do not assume it does. Send yourself a test message and inspect the raw message source, or ask the provider where its `List-Unsubscribe` headers are configured.
Then test the removal flow. Click unsubscribe. Confirm that the address is actually suppressed. If someone replies asking not to hear from you, remove them promptly and keep a record of that choice.
A practical setup for a Shopify store
If your store has never sent cold outreach, keep your first decision boring:
1. Leave your main store domain for customer mail. 2. Keep Shopify Email for opted-in subscribers. 3. Use a separate domain, or at least a dedicated subdomain, for outreach. 4. Authenticate that sender before sending. 5. Use a clear sender name and a real reply address. 6. Include an easy way to opt out and honor it. 7. Watch replies, bounces, and complaints before increasing volume.
The goal is not to make cold outreach risk-free. It is to avoid putting your most important customer mail in the same risk bucket.
Your next step is simple: open your email tool and list every sender address your store uses. If cold outreach shares the domain used for receipts or password resets, separate it before sending the next campaign.