How to Enable DNSSEC Protection for Squarespace Domains: Security Guide
DNSSEC protection automatically secures all eligible Squarespace-managed domains, safeguarding against DNS spoofing and malicious redirects. This security feature uses public and private keys stored in your DNS records as DS or DNSKEY records.
How DNSSEC Works Domain Name System Security Extensions (DNSSEC) verifies domain data integrity as visitors load your site. It automatically creates and manages security keys in your DNS records.
Managing DNSSEC Settings
Disabling DNSSEC:
- Navigate to domains dashboard
- Select your domain
- Click DNS > DNSSEC
- Turn off DNS Security Extensions toggle
- Click Confirm
Note: DNSSEC automatically disables when using custom nameservers.
Adding Third-Party DNSSEC Protection To use alternative DNSSEC protection (like Cloudflare):
- Access domains dashboard
- Select domain
- Click DNS > DNSSEC > Add record
- Enter provider's information:
- Key tag
- Algorithm
- Digest type
- Digest
- Click Save
Re-enabling DNSSEC
- Open domains dashboard
- Select domain
- Click DNS > DNSSEC
- Enable DNS Security Extensions toggle
Troubleshooting Common Issues
Records Incompatible with DNSSEC:
- Disable DNSSEC
- Re-add DNS record
DNSSEC Validation Failure:
- Reset to Squarespace default nameservers
- Re-enable DNSSEC
Remember: You can only have one DNSSEC record per domain, and it's automatically enabled for supported TLDs using Squarespace's default nameservers.