Squarespace SSL certificate pending or "SSL unavailable"
Squarespace issues a free certificate on its own, but only once your domain points at Squarespace correctly. While it cannot see that, the certificate stays pending and visitors get a "not secure" warning.
What to do, in order
- Open Settings, Domains, and click the domain. Look at DNS settings. Squarespace lists the records it expects and marks any that are wrong.
- Fix the records at the company where you bought the domain. You need the CNAME for www pointing at ext-cust.squarespace.com, plus the verification CNAME, and the four A records for the bare domain that Squarespace shows you.
- Delete old records that fight them. An old A record or AAAA record from a previous host stops the certificate. Remove anything for @ or www that Squarespace did not ask for.
- Check for a CAA record. If your domain has one that does not allow letsencrypt.org, the certificate can never be issued. Add letsencrypt.org or remove the CAA record.
- Wait, then retry. After the records are right, give it up to 72 hours. Then use the retry option in the SSL panel.
If it still fails, send me the address and I will tell you which step is broken.
Want the rest of your site checked after it is back? Run a free 40-point check at tinkeraudit.com.