
How to Enable and Manage DNSSEC Protection for Squarespace Domains
DNSSEC protection automatically secures Squarespace domains with supported TLDs against DNS spoofing and malicious redirects. This security feature uses public and private keys stored in DNS records to verify domain data integrity.
How DNSSEC Works
Domain Name System Security Extensions (DNSSEC) uses key pairs to ensure visitors receive unchanged website data. These keys are automatically stored as DS records or DNSKEY records in your DNS settings.
Disabling DNSSEC
DNSSEC automatically disables when using custom name servers. To manually disable:
- Navigate to domain dashboard
- Select your domain
- Go to DNS > DNSSEC
- Toggle off DNS Security Extensions
- Confirm to remove DNSSEC information
Adding Third-Party DNSSEC
To implement third-party DNSSEC protection:
- Access domain dashboard
- Select domain
- Go to DNS > DNSSEC > Add Record
- Enter provider's information:
- Key Tag
- Algorithm
- Digest Type
- Digest
- Save changes
Note: Only one DNSSEC record can be added per domain.
Re-enabling DNSSEC
To re-enable DNSSEC:
- Open domain dashboard
- Select domain
- Navigate to DNS > DNSSEC
- Toggle on DNS Security Extensions
Troubleshooting Common Issues
-
"Record incompatible with DNSSEC" error:
- Disable DNSSEC
- Re-add DNS records
-
"DNSSEC validation failed" error:
- Revert to Squarespace default name servers
- Re-enable DNSSEC
When switching back from custom to default name servers, you'll be prompted to re-enable DNSSEC through the View DNSSEC option.
Related Articles

How to Set Up a Third-Party Subdomain on Squarespace: Step-by-Step Guide
