
DNSSEC Protection Guide: Secure Your Squarespace Domain from Malware
DNSSEC protection comes automatically enabled for all Squarespace-managed domains under the top-level domain, protecting against DNS spoofing and malicious redirects.
Domain Name System Security Extensions (DNSSEC) uses public and private keys stored as DS or DNSKEY records to verify domain data integrity when visitors access your site.
Disabling DNSSEC
DNSSEC automatically disables when using a custom ad server. To manually disable:
- Open domain control panel
- Select domain
- Navigate to DNS > DNSSEC
- Turn off DNS Security Extensions
- Confirm to remove DNSSEC information
Adding Third-Party DNSSEC Protection
To add third-party DNSSEC (like Cloudflare):
- Open domain control panel
- Select domain
- Go to DNS > DNSSEC > Add Record
- Enter provider's information:
- Key Tag
- Algorithm
- Digest Type
- Digest
- Save changes
Note: Only one DNSSEC record can be added per domain.
Re-enabling DNSSEC
To re-enable DNSSEC:
- Open domain control panel
- Select domain
- Go to DNS > DNSSEC
- Turn on DNS Security Extensions
When reverting from a custom ad server, click "View DNSSEC" in the prompt and enable DNS Security Extensions.
Troubleshooting Common Issues
"Records not compatible with DNSSEC":
- Disable DNSSEC
- Re-add DNS record
"DNSSEC validation error" with custom name servers:
- Reset to Squarespace default name servers
- Enable DNSSEC
All DNSSEC management is handled through the domain control panel's DNS settings section.
Related Articles

How to Set Up a Third-Party Subdomain on Squarespace: Step-by-Step Guide
