How to Enable SSL on Squarespace, Solve Certificate Unavailable, Processing, Not Working Error 2026
By Impran M N
Squarespace issues a free SSL certificate for every custom domain automatically, but that doesn't mean your site is actually serving traffic over HTTPS — that's a separate switch you have to flip yourself in Settings. Leave it on the default and search engines can index the insecure version of your site, visitors won't get automatically redirected to the secure one, and you lose the padlock icon that signals trust. This guide covers where that switch lives, what each option actually does, and what to check if the certificate shows as unavailable or gets stuck processing instead of activating.
01Open Settings and find SSL
From your Squarespace dashboard, go to Settings, then scroll down to Developer Tools and select SSL — it's easy to miss because it isn't grouped with Domains & Email, where most people look first for anything domain-security related. At the top of the SSL page you'll see Certificate Status, which should read Active if Squarespace has already issued a certificate for your connected domain. If it reads anything else — Unavailable, Pending, or Processing — the certificate itself hasn't finished issuing yet, and the security preference below won't matter until that resolves.

02Understand the three security preference options
Below the certificate status, Squarespace gives you three radio options: Secure (Preferred), HSTS Secure, and Insecure. Secure directs search engines to index the HTTPS version of your site and automatically redirects any visitor who lands on the insecure URL — this is the setting almost every site should use.
HSTS Secure goes further, forcing browsers to only ever load the secure version and helping prevent downgrade attacks, but it's a stricter setting worth adding only after Secure has been running cleanly for a while. Insecure, the default on some older sites, leaves both versions live and indexable, which is the configuration that causes the missing-padlock complaints people search for.
03Switch to Secure and save
Click the radio button next to Secure (Preferred), then click Save in the top-right corner of the settings panel. The change applies immediately to new requests, but if your site was previously running Insecure, give it a little time for cached versions of your pages to clear out of search engines and browsers. Once saved, load your site in a fresh browser tab and confirm you see the padlock icon and an automatic redirect if you try to load the plain HTTP version of a page.

04Fix a certificate stuck on Unavailable
If Certificate Status shows Unavailable instead of Active, the most common cause is a DNS mismatch — your domain isn't pointing correctly at Squarespace's servers, so Squarespace's certificate authority can't verify ownership to issue one. Go to Domains & Email and confirm the domain's DNS records match what Squarespace's connection instructions specify exactly; even a stray or missing record blocks issuance. If you recently connected the domain, this is often simply a timing issue rather than a misconfiguration — see the next step.
05Wait out a certificate stuck on Processing
SSL certificates aren't instant — after connecting a new domain or making a DNS change, Squarespace typically needs anywhere from a few minutes up to 72 hours to issue and activate a certificate, depending on how quickly your DNS changes propagate. During this window the status will read Processing and the Security Preference options may be greyed out or unavailable to change, which is expected rather than a sign of failure. Resist changing DNS settings again during this window, since each change can restart the verification clock and extend the wait.
06Verify SSL is working across devices
Once status shows Active and Secure is selected, test the site on both desktop and mobile, and from a network you don't normally use if possible, since local DNS caching can make a fixed site look broken to you longer than to everyone else. Look for the padlock in the address bar and try loading a plain http:// version of a page to confirm it redirects to https:// automatically — that redirect confirms Secure is actually doing its job, not just switched on in settings.
Frequently asked questions
Why does my Squarespace SSL certificate say Unavailable?
Almost always a DNS mismatch — your domain's DNS records don't match what Squarespace needs to verify ownership and issue the certificate. Check Domains & Email and compare your records against Squarespace's connection instructions exactly.
How long does it take for Squarespace SSL to finish processing?
Typically a few minutes to a few hours, but it can take up to 72 hours depending on DNS propagation. Avoid making further DNS changes during this window, since each change can restart the wait.
What's the difference between Secure and HSTS Secure?
Secure redirects insecure traffic to the HTTPS version automatically. HSTS Secure adds a stricter enforcement that forces browsers to only ever load the secure version, which helps prevent downgrade attacks but is best added after Secure has already been working reliably.
Do I need to pay extra for SSL on Squarespace?
No — Squarespace includes a free SSL certificate automatically with every custom domain connected to a site on any current plan; there's no separate purchase or app needed.
Why don't visitors see the padlock even though my certificate is Active?
Check that Security Preference is actually set to Secure and not left on Insecure — an active certificate only secures traffic when that setting directs visitors to the HTTPS version, otherwise both versions stay live and unencrypted requests go through.
About the author

Impran M N
I've been hooked on technology for as long as I can remember — especially the new tools and AI apps that seem to land every other week. Easy Tech Tuts is where I write up whatever I've just worked out: I do the task in the real product, record the screen, and turn it into the guide I wish I'd found first.



