DNSSEC Protection Now Automatic for All Squarespace Domain Users
DNSSEC automatically protects all Squarespace-managed domains with compatible TLDs against DNS spoofing and malicious redirects. This security feature uses public and private keys stored in your DNS records as DS or DNSKEY records.
alt text
Managing DNSSEC Settings
To disable DNSSEC:
- Open domains panel
- Select your domain
- Click DNS > DNSSEC
- Turn off DNS Security Extensions
- Click Confirm
Note: DNSSEC automatically disables when using custom name servers.
Adding Third-Party DNSSEC Protection
To add external DNSSEC protection:
- Open domains panel
- Select domain
- Click DNS > DNSSEC > Add Record
- Enter required fields:
- Key Label
- Algorithm
- Digest Type
- Digest
Important: Only one DNSSEC record can be added per domain.
Re-enabling DNSSEC
To re-enable DNSSEC:
- Open domains panel
- Select domain
- Click DNS > DNSSEC
- Turn on DNS Security Extensions
When switching back to Squarespace's default name servers, you'll be prompted to re-enable DNSSEC.
Troubleshooting Common Issues
-
"Records not compatible with DNSSEC" error:
- Disable DNSSEC
- Re-add DNS record
-
"DNSSEC validation error" with custom name servers:
- Reset to Squarespace's default name servers
- Re-enable DNSSEC