Shopify Checkbulk checker
how it works

How to tell if a site uses Shopify

There are six signals worth reading. Four of them settle the question on their own. Below is each one, what it proves, and the command that reads it by hand — so you can check our work

  1. 01

    Shopify response headers

    strong — served by Shopify's own infrastructure

    Shopify's storefront renderer stamps headers nothing else sends: x-shopid, x-sorting-hat-shopid, x-sorting-hat-podid, x-shopify-stage. They name the shard and the shop id serving the page. A site can hide its theme. It cannot hide the machine that rendered it.

    curl -sI https://example.com | grep -i shop
  2. 02

    myshopify.com redirect

    strong — the domain resolves to a Shopify store address

    Every Shopify store keeps a permanent name at store-name.myshopify.com. Stores redirect through it when a custom domain is unfinished, or when a second domain points at the shop. One hop is all it takes.

    curl -sIL https://example.com | grep -i location
  3. 03

    Shopify CDN assets

    strong — the page's images and scripts come from Shopify

    Theme images, product photos and compiled assets load from cdn.shopify.com and cdn.shopifycloud.com. Newer stores serve them from /cdn/shop/files/ and /cdn/shop/products/ on their own domain. A headless store still pulls its media from here.

    view source, search for cdn.shopify
  4. 04

    Shopify script fingerprints

    strong — Shopify's own JavaScript is on the page

    The storefront ships a global Shopify object holding the shop domain, the theme id and the locale. Alongside it sit ShopifyAnalytics, the monorail-edge.shopifysvc.com beacon and a shopify-checkout-api-token meta tag. The store needs all of it to work, so it is hard to remove.

    view source, search for window.Shopify
  5. 05

    Shopify cart endpoint

    weak on its own — confirms a Shopify backend answers

    Every Shopify storefront answers /cart.js with a JSON cart holding a token and an item_count. A custom front end on Shopify's commerce backend often still exposes it. We treat it as support, not a verdict, because a proxy can fake it.

    open https://example.com/cart.js
  6. 06

    DNS pointed at Shopify

    strong — the domain itself is delegated to Shopify

    Custom domains on Shopify point their www record at shops.myshopify.com. This is the one signal that survives a site being down, password-protected or blocking us. So it is our fallback.

    dig CNAME www.example.com

Why we say Unclear instead of guessing

Two situations break a careless detector. A headless store runs its front end on Next.js or Hydrogen. It serves almost none of the usual markup, while still being a Shopify store. A site behind an aggressive firewall answers with a challenge page carrying no signals at all.

In both cases a yes or a no would be a coin flip. So when nothing strong lands, we say Unclear and list every signal we looked for. And when we could not read the site at all, we say that — never Not Shopify. A failed fetch is not a verdict.

Run it yourself — one URL, no signup, and the evidence table is the same one described above

check a site