How to Enable and Manage DNSSEC Protection for Squarespace Domains
DNSSEC protection automatically secures Squarespace-managed domains with supported TLDs against DNS spoofing and malicious redirects. This security feature uses public and private keys stored as DS or DNSKEY records in your DNS settings.
How DNSSEC Works Domain Name System Security Extensions (DNSSEC) verifies that domain data remains unaltered when visitors access your website through cryptographic key pairs stored in your DNS records.
Managing DNSSEC Settings
To Disable DNSSEC:
- Navigate to domain dashboard
- Select your domain
- Go to DNS > DNSSEC
- Turn off DNS Security Extensions
- Click Confirm
To Reactivate DNSSEC:
- Navigate to domain dashboard
- Select your domain
- Go to DNS > DNSSEC
- Turn on DNS Security Extensions
Adding Third-Party DNSSEC Protection
- Open domain dashboard
- Select your domain
- Go to DNS > DNSSEC > Add record
- Enter provider's information for:
- Key Tag
- Algorithm
- Digest Type
- Summary
- Click Save
Note: Only one DNSSEC record can be added per domain.
Troubleshooting Common Issues
"Records not compatible with DNSSEC":
- Disable DNSSEC
- Re-add DNS record
"DNSSEC validation failed":
- Reset to Squarespace's default nameservers
- Re-enable DNSSEC
Important: DNSSEC automatically disables when switching to custom nameservers. When reverting to Squarespace's default nameservers, you'll be prompted to reactivate DNSSEC protection.