How DNSSEC Protection Works with Squarespace Domains: Complete Guide
DNSSEC protection automatically safeguards all eligible Squarespace-managed domains, defending against DNS spoofing and malicious redirects by using public and private keys stored in DS or DNSKEY records.
How DNSSEC Works
DNSSEC (Domain Name System Security Extensions) verifies domain data authenticity when visitors access your site through encrypted key pairs, ensuring data integrity and preventing tampering.
Disabling DNSSEC
DNSSEC automatically disables when using custom name servers. To manually disable:
- Access domain dashboard
- Select target domain
- Navigate to DNS > DNSSEC
- Toggle off DNS Security Extension
- Confirm to remove DNSSEC information
Adding Third-Party DNSSEC Protection
To implement third-party DNSSEC (like Cloudflare):
- Open domain dashboard
- Select domain
- Go to DNS > DNSSEC > Add Record
- Enter provider's DS record information:
- Key Tag
- Algorithm
- Digest Type
- Digest
- Save changes
Note: Only one DNSSEC record can be added per domain.
Re-enabling DNSSEC
For supported domains, DNSSEC enables automatically. To manually re-enable:
- Access domain dashboard
- Select domain
- Go to DNS > DNSSEC
- Toggle on DNS Security Extension
Troubleshooting Common Issues
Record Compatibility Error:
- Disable DNSSEC
- Re-add DNS records
DNSSEC Validation Failure:
- Restore Squarespace default name servers
- Re-enable DNSSEC
When switching from custom to default name servers, enable DNSSEC through the prompt window by clicking "View DNSSEC" and activating DNS Security Extension.