Squarespace

Force HTTPS on Squarespace

Squarespace automatically issues and renews SSL certificates for both Squarespace-hosted domains and custom domains connected through its system, with HTTPS enforced by default across the platform.

Confirming it's active

Under Settings → Advanced → SSL, ensure the setting is switched to "Secure" rather than "Not Secure." This is on by default for new sites, but worth confirming after a domain migration.

Common cause of delay

If SSL shows as pending for more than a day or two after connecting a domain, it's almost always a DNS configuration issue — verify your domain's DNS records match exactly what Squarespace's domain connection guide specifies for your setup.

What Squarespace's SSL toggle actually controls versus what's automatic

The Settings → Advanced → SSL toggle controls enforcement, redirecting HTTP to HTTPS, while certificate issuance itself happens automatically in the background regardless of the toggle's state — meaning even before you explicitly enable enforcement, a certificate is likely already provisioned and ready.

How to confirm a custom domain's certificate status directly

The same SSL settings panel shows the current certificate status for a connected custom domain, including whether it's still pending issuance — checking here first, before assuming something is broken, quickly rules out the most common cause of a temporarily insecure custom domain.

Why Squarespace's approach removes manual renewal entirely from your responsibility

Because Squarespace controls both hosting and certificate issuance end to end, there's no renewal date to track or CSR to manage — the platform handles the entire certificate lifecycle automatically for the life of your subscription, the same operational simplicity covered across most fully managed platforms in this category.

What Squarespace's SSL status indicators actually mean at each stage

The SSL panel shows distinct states as a certificate moves through provisioning — pending while validation and issuance are underway, and active once the certificate is fully issued and enforcement can be safely enabled; understanding these stages helps set realistic expectations rather than assuming a stuck or broken process.

Why Squarespace handles subdomains differently from a self-managed wildcard setup

Squarespace's certificate coverage for connected subdomains is managed automatically as part of the platform's own certificate provisioning, rather than requiring you to separately request or configure wildcard coverage the way a self-managed server would — one less manual step compared to platforms without this level of automation.

What to do if a recently transferred domain shows an SSL warning temporarily

A domain recently transferred to Squarespace can show a brief SSL warning while the platform completes its own certificate issuance process for the newly connected domain — this typically resolves within a few hours as DNS settles and Squarespace's automated issuance completes.

Why this managed approach scales well even as a site grows more complex

As a Squarespace site adds more pages, commerce functionality, or connected subdomains over time, the underlying certificate and HTTPS handling scales automatically without requiring any additional configuration on your part — a meaningful advantage over a self-managed setup where growing complexity often means growing certificate management overhead too.

What happens to SSL status during a plan upgrade or downgrade

Changing your Squarespace plan tier doesn't affect SSL provisioning for an already-connected domain, since certificate issuance is tied to domain connection rather than specific plan features — SSL remains active continuously through a plan change.

Why Squarespace doesn't offer OV or EV certificate options

Squarespace's platform is built around DV certificates specifically, since its target audience of small businesses and individual creators rarely has the specific compliance or contractual need for higher validation tiers — a reasonable platform-level trade-off prioritizing simplicity over accommodating a less common use case.