
How DNSSEC Protection Works with Squarespace Domains
DNSSEC automatically protects all Squarespace-managed domains with top-level domains against DNS spoofing and malicious redirects. This security feature uses public and private keys stored as DS or DNSKEY records in your DNS configuration.
How DNSSEC Works on Squarespace
Domain Name System Security Extensions (DNSSEC) verifies domain data integrity when visitors access your site by using encrypted keys. These are automatically maintained in your DNS records.
Managing DNSSEC Settings
To disable DNSSEC:
- Access domain control panel
- Select your domain
- Navigate to DNS > DNSSEC
- Toggle off DNS Security Extensions
- Confirm the change
DNSSEC automatically disables when using custom ad servers. To re-enable:
- Access domain control panel
- Select your domain
- Navigate to DNS > DNSSEC
- Toggle on DNS Security Extensions
Using Third-Party DNSSEC Protection
You can add third-party DNSSEC protection (like Cloudflare) by:
- Open domain control panel
- Select your domain
- Go to DNS > DNSSEC > Add Record
- Enter provider's information:
- Key Tag
- Algorithm
- Digest Type
- Digest
- Save changes
Note: Only one DNSSEC record can be active per domain.
Troubleshooting Common Issues
Records Not Compatible with DNSSEC:
- Disable DNSSEC
- Re-add DNS record
DNSSEC Validation Error:
- Reset name servers to Squarespace defaults
- Re-enable DNSSEC
These steps ensure proper domain security while maintaining compatibility with your DNS configuration.
Related Articles

Why Domain Changes Take Up to 48 Hours to Propagate Worldwide
