Playbook · Custom domain / SSL not connecting

Shopify custom domain / SSL not connecting or pending — DNS A/CNAME, Cloudflare proxy, www redirect.

Written for a Shopify DTC owner whose custom domain stays Connecting / SSL pending, apex or www will not open, Cloudflare orange-cloud proxy breaks Shopify certificate provisioning, or www ↔ apex redirects loop — usually wrong A / CNAME targets, proxy still on, primary domain unset, or an old host still answering. DIY-first: prove Domains status and live DNS, fix records and proxy, set primary + redirects, wait for SSL. Distinct from store stuck on password page / coming soon, Markets currency / price wrong for country, and cookie consent / GDPR banner blocking checkout. No earnings claims, no invented case studies.

Nico at Latch AI Ops · Sep 8, 2026 · ~12 minute read

Buy the 72-hour install — $997Password pageMarkets currencyMerchant FAQ

01

Custom domain / SSL pending — not password page, Markets currency, or cookie banner.

Several products can look like “the store URL will not open.” They do not share a settings panel. This page is only when Settings → Domains shows Connecting / SSL pending, or the custom host fails TLS / DNS while .myshopify.com still works. A storefront that opens but stays on Enter using password / Coming soon is password page stuck online. Wrong currency or price for a buyer country is Markets currency wrong. A cookie / GDPR banner covering Add to cart on an already-open storefront is cookie banner blocking checkout. This page is only: custom domain / SSL not connecting.

Six ordinary reasons the domain stays pending: apex A or www CNAME still on the old host / wrong Shopify targets, Cloudflare (or another CDN) orange-cloud proxy still on so Shopify cannot issue TLS, www ↔ apex redirect loop or primary domain unset, AAAA / leftover records fighting the A record, SSL still provisioning after a fresh DNS cutover, or you are debugging password page / Markets FX / cookie banner instead. Walk them in that order. You already pay for Shopify Domains tooling. You do not need another seat to point DNS at Shopify.

02

Prove Domains status, DNS A/CNAME, and the TLS error on the custom host.

Open Settings → Domains. Screenshot every hostname (apex, www, Markets country domains) and the status chip (Connected / Connecting / SSL pending / Error). From a machine outside your office Wi-Fi, dig or nslookup the apex A / AAAA and the www CNAME. In Cloudflare (or your DNS host), screenshot proxy status (orange cloud vs DNS-only). Open the custom host in a logged-out browser and capture the exact TLS / connection error — not the .myshopify.com URL.

Honest proof: if .myshopify.com loads the catalog and the custom host fails DNS / TLS / stays Connecting, stay on this page. If the custom host loads but shows Enter using password / Coming soon, leave for password page stuck online. If the host loads and currency / price is wrong for a country, use Markets currency wrong. If the host loads and a cookie banner blocks buy buttons, use cookie banner blocking checkout. Do not mix those proofs.

03

DNS A / CNAME / AAAA still wrong or pointing at the old host.

Shopify tells you the exact apex A target(s) and www CNAME in Settings → Domains after you add the hostname. Old GoDaddy / Namecheap / Squarespace / Vercel / Netlify A or CNAME records, leftover AAAA, or a CNAME on the apex (where your registrar forbids it) keep Domains on Connecting forever. Staff who only test .myshopify.com never see the failure.

Fix: copy Shopify’s current recommended A / CNAME values into the DNS host that actually answers for the domain (check NS first). Remove conflicting A / AAAA / CNAME on the same name. Save, wait for TTL, re-check dig, then hit Verify / refresh in Domains. Do not “fix” this by putting the store behind a random parking page. Password page and Markets FX settings live elsewhere; they do not fix DNS.

04

Cloudflare orange-cloud proxy blocking Shopify SSL provisioning.

Cloudflare (and some other CDNs) orange-cloud / proxied mode terminates TLS at the edge. Shopify then cannot complete its own certificate challenge for that hostname, so Domains stays SSL pending or shows intermittent TLS errors even when dig looks “right” (because dig shows Cloudflare IPs, not Shopify’s). The same class of ticket shows up after someone “turned on CDN for speed” on launch day.

Fix: for the Shopify apex and www records, set proxy to DNS-only (grey cloud) until Settings → Domains shows Connected with a valid SSL. Do not force Full (strict) on Cloudflare until Shopify owns the cert. After Connected, follow Shopify’s current guidance before re-enabling any proxy. Cookie consent and Markets currency are still different products — they do not clear SSL pending.

05

www ↔ apex redirect loop or primary domain not set.

Both apex and www can be Connected in Domains while the wrong one is primary, or while the DNS host / Cloudflare Page Rules / Bulk Redirects send www → apex and Shopify also redirects the other way. Buyers then see ERR_TOO_MANY_REDIRECTS or land on the host you do not share in ads / email / bio. Markets country domains add another redirect hop if mis-primary’d.

Fix: Settings → Domains — set the hostname you actually market as Primary. Keep one owner of www ↔ apex redirects (prefer Shopify’s domain redirect once both hosts are Connected). Remove competing Page Rules / forwarding at the registrar. Confirm Markets domains are Connected separately; currency / price bugs after the domain works are Markets currency wrong, not this page.

06

SSL certificate stuck pending after DNS looks correct.

After A / CNAME match and proxy is DNS-only, Shopify still needs time to issue TLS. Fresh cutovers, CAA records that omit Let’s Encrypt / Google Trust Services issuers Shopify uses, or a recent domain transfer can leave SSL pending for longer than the dashboard’s optimistic copy. Opening the host too early produces NET::ERR_CERT_COMMON_NAME_INVALID or similar.

Fix: re-verify dig matches Shopify targets, confirm CAA allows issuance (or remove a blocking CAA), wait through TTL, then use Domains → refresh / re-check connection. Do not paste a custom third-party cert unless Shopify’s current Domains UI asks for one. If the storefront finally opens but still shows the password / coming soon gate, switch to password page stuck online— that is Online store password, not SSL.

07

You tested password page, Markets currency, or cookie banner instead.

A storefront that opens on the custom domain but stays on Enter using password / Coming soon is password page stuck online. Wrong Markets currency or unit price for a buyer country is Markets currency wrong. A cookie consent / GDPR banner that blocks Add to cart after the domain is Connected is cookie banner blocking checkout.

The only honest test for this page: Settings → Domains status for the marketed hostname is Connecting / SSL pending / Error (or the browser fails TLS / DNS on that host); dig shows wrong or proxied targets; fixing A/CNAME, Cloudflare DNS-only, primary + redirects, and SSL wait moves Domains to Connected. Anything else is a different product.

08

When to stay DIY vs pay $997.

Stay DIY if you can spend one afternoon on the list above: prove Domains status and live DNS, fix A / CNAME / AAAA, set Cloudflare to DNS-only until SSL connects, set primary + www redirects, wait for the certificate, and stop confusing password page / Markets FX / cookie banner with domain connection. That is the whole playbook. No agency required. Short answers also live on the merchant FAQ. Related pages: password page stuck online, Markets currency wrong, cookie banner blocking checkout.

Pay for help when the work is not the DNS row — it is connecting the stack you already have so lead capture is not dying in DMs, storefront and checkout-ready exceptions land in a channel you already check, and the live store is one workflow instead of a spreadsheet plus a Slack bot you forgot. That is the Latch AI Ops install.

What $997 USD one-time buys: lead capture on the live store, ops alerts in a channel you already check, and a checkout-ready workflow. 72 hours after collaborator access, not after payment. One live Shopify store. Access plus a delivery thread. Store URL collected at checkout. Not a SaaS seat, not a theme rebuild retainer, not a conversion guarantee, not a brand or theme job.

Other shops’ public ranges, not testimonials: a checkout / ops install typically runs $500–$2,500. A full ops consulting block typically runs $2,000–$5,000. $997 is the cheap end of that work, sold as a 72-hour install of three systems — not as an earnings number or conversion-lift claim.

What it does not buy: more orders, recovered revenue, a forever Connected SSL badge, or a case study. Latch AI Ops has not published customer proof because there are no customers yet. You are buying the install.

Checkout is on Whop. Operator is Nico. United States offer. You can revoke collaborator access after handoff. We do not take owner passwords.