How to Enable and Manage DNSSEC Protection for Squarespace Domains
DNSSEC secures your Squarespace domain by automatically protecting against DNS spoofing and malicious site redirections. This security feature is enabled by default on all Squarespace-managed domains with compatible TLDs.
How DNSSEC Works DNSSEC (Domain Name System Security Extensions) uses public and private key pairs to verify domain data authenticity. These keys are automatically stored in your DNS records as DS or DNSKEY records.
Managing DNSSEC Settings
Disabling DNSSEC:
- Open Domains panel
- Select your domain
- Navigate to DNS > DNSSEC
- Disable DNS Security Extensions
- Confirm the action
Re-enabling DNSSEC:
- Open Domains panel
- Select your domain
- Navigate to DNS > DNSSEC
- Enable DNS Security Extensions
External DNSSEC Protection
To add third-party DNSSEC (like Cloudflare):
- Open Domains panel
- Select your domain
- Go to DNS > DNSSEC > Add Record
- Enter provider's information:
- Key Tag
- Algorithm
- Digest Type
- Digest
- Save the record
Note: Only one DNSSEC record can be active per domain.
Troubleshooting Common Issues
Records Incompatible with DNSSEC:
- Disable DNSSEC
- Re-add DNS record
DNSSEC Validation Failure:
- Restore Squarespace default nameservers
- Re-enable DNSSEC
Important Notes:
- DNSSEC automatically disables with custom nameservers
- When switching back to Squarespace nameservers, you'll need to re-enable DNSSEC
- Contact your third-party DNSSEC provider for specific record values