DNSSEC Protection Now Automatic for All Supported Squarespace Domains
DNSSEC protection provides automatic security for Squarespace-managed domains with supported TLDs by preventing DNS spoofing and malicious redirects. It uses public and private keys stored in DNS records as DS or DNSKEY records.
For domains managed by Squarespace:
- DNSSEC is enabled by default when TLD supports it
- Protection automatically disables with custom nameservers
- Only one DNSSEC record can be added per domain
Disabling DNSSEC:
- Navigate to domains dashboard
- Select your domain
- Go to DNS > DNSSEC
- Turn off DNS Security Extensions
- Click Confirm in the popup window
Adding Third-Party DNSSEC:
- Access domains dashboard
- Choose domain to edit
- Go to DNS > DNSSEC > Add record
- Input provider's information:
- Key Tag
- Algorithm
- Digest Type
- Digest
- Save changes
Re-enabling DNSSEC:
- Open domains dashboard
- Select domain
- Navigate to DNS > DNSSEC
- Enable DNS Security Extensions
Common Issues and Solutions:
- "Records not compatible with DNSSEC": Disable DNSSEC, then add DNS record
- "DNSSEC validation error": Revert to Squarespace nameservers and enable DNSSEC
Note: When using custom nameservers, you'll need to manually manage DNSSEC settings. Contact your third-party DNSSEC provider for specific configuration values.