
How DNSSEC Protection Works with Squarespace Domains
DNSSEC automatically protects Squarespace-managed domains with compatible TLDs against DNS spoofing and malicious redirects by using public and private keys stored in DS or DNSKEY records.
How DNSSEC Works with Squarespace Domains
DNSSEC (Domain Name System Security Extensions) verifies domain data authenticity as visitors load your site. The security keys are automatically stored in your DNS records, requiring no manual setup for basic protection.
Disabling DNSSEC
DNSSEC automatically disables when using custom nameservers. To manually disable:
- Open domains dashboard
- Select your domain
- Click DNS > DNSSEC
- Turn off DNS Security Extensions
- Confirm the change
Adding Third-Party DNSSEC Protection
To use third-party DNSSEC (like Cloudflare):
- Open domains dashboard
- Select your domain
- Click DNS > DNSSEC > Add record
- Enter provider's information:
- Key tag
- Algorithm
- Digest type
- Digest
- Click Save
Note: Only one DNSSEC record is allowed per domain.
Re-enabling DNSSEC
To re-enable DNSSEC:
- Open domains dashboard
- Select your domain
- Click DNS > DNSSEC
- Turn on DNS Security Extensions
Troubleshooting Common Issues
Records Incompatible with DNSSEC:
- Disable DNSSEC
- Add DNS record again
DNSSEC Validation Failure:
- Reset to Squarespace default nameservers
- Re-enable DNSSEC
These steps ensure proper domain security while maintaining flexibility for custom configurations.
Related Articles

How to Set Up a Third-Party Subdomain on Squarespace: Step-by-Step Guide
