Bluesky Custom Domain DID DNS Generator
Generate bulletproof DNS TXT records for your custom domain, resolve your permanent DID identifier, and verify live DNS propagation across Cloudflare, Namecheap, and GoDaddy.
01. Bluesky Account & DID
Queries public ATProto API client-side to fetch your cryptographic DID.
02. Desired Custom Domain
Enter your apex domain (e.g. alice.com) or subdomain (e.g. news.org).
_atproto in the Name field. Cloudflare automatically handles root domain mapping.
Live DNS Propagation Verifier
Test if your TXT record is visible globally via Google DNS-over-HTTPS (DoH)
Method 2 Alternative: HTTP Well-Known File (.well-known/atproto-did) ↓
If you have web hosting and prefer not to edit DNS, create a public static file at:
File contents (plain text, single line):
did:plc:z72i7hdynmk6r22z27h6tvur
How to Complete Verification Inside the Bluesky App
Follow these 4 steps once your DNS record is live.
Go to Settings
Open Bluesky → Settings → Account → Handle → tap "I have my own domain".
Enter Your Domain
Type your exact domain (e.g. alice.com) and select the "DNS Panel" verification tab.
Add DNS TXT Record
Paste the generated TXT record into your DNS provider and run our Live Test button above to confirm propagation.
Click Verify
Tap "Verify DNS Record" in Bluesky. Your profile instantly converts to your verified custom handle!
Frequently Asked Questions
Common issues and solutions for Bluesky domain verification.
What happens to my followers and posts when I switch to a custom domain? ↓
What is the double domain error on Namecheap and GoDaddy? ↓
_atproto.yourdomain.com in Namecheap, Namecheap saves it as _atproto.yourdomain.com.yourdomain.com. This breaks verification. On Namecheap and GoDaddy, only enter _atproto in the Host field!
How do I use a subdomain (e.g., @press.brand.com)? ↓
press.brand.com, the Host field in Cloudflare must be _atproto.press. The Value field remains identical (did=did:plc:...).
Does setting up a custom handle cost money? ↓
Understanding the AT Protocol Identity Architecture
The Authenticated Transfer Protocol (ATProto) powers Bluesky and differs fundamentally from traditional federated networks like Mastodon (ActivityPub) or centralized platforms like Twitter/X. On legacy networks, your handle is your identity. If you change your domain or the server shuts down, you lose your social graph.
1. Decentralized Identifier (DID)
A permanent, cryptographic string (e.g., did:plc:z72i7hdynmk6r22z27h6tvur) that anchors your cryptographic keypairs, user data repository, and public signing keys. Even if you change your domain handle 10 times, your DID never changes.
2. Human-Readable Handle
Your custom domain (e.g., alice.com) acts as a human-friendly pointer to your DID. When someone searches for your handle, Bluesky queries DNS TXT records to confirm your domain points back to your specific DID.
Common Troubleshooting & Verification Pitfalls
- Cloudflare Proxy Status (Orange vs Grey Cloud): Because TXT records are DNS-only, Cloudflare does not proxy TXT records through its HTTP edge. However, ensure that your root CNAME or A records do not conflict with the
_atprotosubdomain. - TTL Caching Delays: DNS propagation can take between 2 minutes and 24 hours depending on your registrar’s Time to Live (TTL) settings. If verification fails immediately, wait 5 minutes and test resolution using the Google DNS-over-HTTPS diagnostic tester above.
- Subdomain Brand Verification for Organizations: Media organizations, tech startups, and enterprises frequently set up wildcard or subdomain handles for their staff. For example, a company owning
brand.comcan issueceo.brand.comandpress.brand.comby simply adding separate_atproto.ceoand_atproto.pressTXT records pointing to each team member’s respective DID.