DNSSEC Protection Guide: Secure Your Squarespace Domain from Malware
DNSSEC protection is automatically enabled for all Squarespace-managed domains with top-level domain support. This security feature prevents DNS spoofing and malicious domain redirects through public and private key verification stored as DS or DNSKEY records.
How DNSSEC Works
DNSSEC (Domain Name System Security Extensions) verifies domain data authenticity when visitors access your site. The system uses encrypted keys stored in your DNS records to validate domain information and prevent tampering.
Disabling DNSSEC
DNSSEC automatically disables when switching to a custom ad server. To manually disable:
- Access domain control panel
- Select target domain
- Navigate to DNS > DNSSEC
- Turn off DNS Security Extensions
- Confirm the action
Adding Third-Party DNSSEC Protection
To implement third-party DNSSEC (like Cloudflare):
- Open domain control panel
- Select domain
- Go to DNS > DNSSEC > Add Record
- Enter provider's information:
- Key Tag
- Algorithm
- Digest Type
- Digest
- Save changes
Note: Only one DNSSEC record can be added per domain.
Re-enabling DNSSEC
To re-enable DNSSEC:
- Access domain control panel
- Select domain
- Go to DNS > DNSSEC
- Enable DNS Security Extensions
Troubleshooting Common Issues
Records Not Compatible:
- Disable DNSSEC
- Re-add DNS record
DNSSEC Validation Error:
- Reset to Squarespace default name servers
- Re-enable DNSSEC
For domains using custom name servers experiencing email issues, reset to Squarespace defaults before enabling DNSSEC.