In Squarespace, open your domains dashboard, click your domain, then DNS, then DNS Settings, and add each record under Custom Records with Add record. SPF and DMARC are TXT records, and DKIM is a TXT or CNAME record depending on the service that sends your email.
These three records work together. SPF lists the services allowed to send email for yourbusiness.com. DKIM is a digital signature that proves an email really came from your domain. DMARC tells receivers what to do when an email fails both checks, and sends you reports about it. Gmail and Yahoo expect all three from anyone sending in bulk, and without them more of your email lands in spam.
If your domain came from Google Domains
Squarespace took over all Google Domains registrations and accounts in September 2023, and moved the domains over in the months that followed. If you bought your domain from Google, you now manage it in the Squarespace domains dashboard at account.squarespace.com/domains, with the same steps as any other Squarespace domain.
Two things catch people out after the move:
- Custom name servers came across as they were. If your domain used other name servers at Google, such as Cloudflare's, it still does, and your records belong there (see Step 1).
- Forwarding may have stopped on those domains. Squarespace says domain and email forwarding from Google can stop working on a migrated domain with custom name servers, and has a separate guide to restoring it. Forwarding only receives email, so it doesn't change the steps below for email you send.
Step 1: Check where your DNS is managed
Name servers are the servers that tell the rest of the internet where your DNS records live. In your domain's settings, click DNS, then Domain Nameservers.
- Squarespace name servers: add the records in Squarespace, as described below.
- Custom name servers: Squarespace says the records in its DNS settings won't apply to the domain. Add them at the company those name servers belong to instead.
- A domain registered elsewhere and connected to your Squarespace site by DNS Connect: add the records where the domain is registered. Only domains connected by Nameserver Connect use Squarespace's DNS settings.
Step 2: Get the Name field right
Squarespace adds your domain to the end of whatever you type in the Name field.
- For the main domain, yourbusiness.com, enter
@. - For DMARC, enter
_dmarc. - For Google Workspace DKIM, enter
google._domainkey.
If you type the full name, you end up with a record at _dmarc.yourbusiness.com.yourbusiness.com, and receivers won't find it. Squarespace may also ask for your password or two-factor code before it lets you add a record.
Step 3: Know what Squarespace has already added
Squarespace adds some records on its own, so look through your DNS settings before you start:
- Anti-spam records. When you register or connect a domain by name servers, Squarespace adds three TXT records (SPF, DKIM and DMARC) that stop anyone sending email from a domain that has no email service. Squarespace removes them automatically when you add your own email records, and they can't be added back by hand. That's expected, so don't worry when they disappear.
- Email forwarding. If you use Squarespace's email forwarding, it adds its own records in an Email forwarding section, and Squarespace's email DNS guide says these include a DMARC record. They can't be removed while a forwarding rule is active.
- Google Workspace. If you signed up for Google Workspace through Squarespace, the MX records (where your email is delivered) are added for you. Otherwise use Add preset and choose Google Workspace. The preset is for MX records. Add SPF, DKIM and DMARC yourself as below.
Step 4: Add or update your SPF record
- In DNS Settings, scroll to Custom Records and look for a TXT record with Name
@whose data starts withv=spf1. - If there is one, edit it (hover over it and click the pencil) rather than adding another. A domain can only have one SPF record.
- If there's none, click Add record, choose TXT as the Type, and enter
@in Name. - In the data field (labeled Text or Data), enter your SPF record. For Google Workspace:
v=spf1 include:_spf.google.com ~all
- Click Save.
Don't put quotation marks around the value. Squarespace says they can cause problems depending on your name servers.
If another service also sends email as you, its include goes in the same record, before ~all. Use the exact value from that service's help pages, and keep the total under 10 DNS lookups. Each include: uses at least one. Squarespace says that if you add SPF records separately, it merges them into one. Even so, check afterward that your domain publishes a single SPF record. If you see a "Custom records not saved" error, Squarespace's advice is to delete your SPF records and add them again.
Step 5: Add your DKIM records
The service that sends your email creates the DKIM key. You publish it in your DNS. Each service that sends as you needs its own.
Google Workspace gives you a TXT record in the Admin console under Apps, Google Workspace, Gmail, Authenticate email:
- Click Add record and choose TXT.
- In Name, enter
google._domainkey. - In the data field, paste the full value from the Admin console. It starts with
v=DKIM1; k=rsa; p=. - Click Save, then go back to the Admin console and click Start authentication.
Squarespace supports DKIM records up to 2048 bits, so you can paste the whole key into one record without splitting it.
Mailchimp and many other services give you CNAME records instead. A CNAME record points one name at another, so the service can look after the key for you. Mailchimp's two look like this:
| Type | Name | Data |
|---|---|---|
| CNAME | k2._domainkey | dkim2.mcsv.net |
| CNAME | k3._domainkey | dkim3.mcsv.net |
Copy the exact names and values your own service shows, because they differ between services and sometimes between accounts. Enter only the part before your domain in Name, and paste values exactly; one missing character breaks the key.
Step 6: Add a DMARC record
- Click Add record and choose TXT.
- In Name, enter
_dmarc. - In the data field, enter:
v=DMARC1; p=none; rua=mailto:dmarc-reports@yourbusiness.com
- Click Save.
p=none is monitoring mode, so nothing changes for your email yet. The rua address is where receivers send daily reports about who is sending as you. Change it to a mailbox you read. Once the reports show all your genuine email passing, change p=none to p=quarantine.
Squarespace allows only one DMARC record per domain. Check the whole DNS settings page for an existing _dmarc record first, including the Email forwarding section. If forwarding has already added one, don't add a second; ask Squarespace support how to change its settings. Add SPF and DKIM first, too. A DMARC record on its own doesn't make your email pass anything.
Step 7: Check it worked
Squarespace gives custom records a 4-hour TTL (how long other servers may keep showing the old value) and says changes can take 24 to 48 hours. Once they've had time, send one email to your free test address. The report checks SPF, DKIM, DMARC and alignment (whether those checks passed for yourbusiness.com itself), gives a verdict for Gmail, Google Workspace, Outlook.com, Microsoft 365 and Yahoo, and shows the exact record to change if anything is still wrong.
Checked against: Squarespace Help Center, DNS records for email · Squarespace Help Center, Adding TXT records · Squarespace Help Center, Edit your domain's DNS records · Squarespace Help Center, Add a third-party email preset · Squarespace Help Center, Review, change, or reset your domain's nameservers · Squarespace Help Center, Troubleshooting issues with DNS records · Squarespace Help Center, About the Google Domains migration to Squarespace · Squarespace Help Center, Email forwarding with a Squarespace domain · Google Workspace Admin Help, Set up DKIM.