🦋
Bluesky DNS
AT Protocol Identity & DNS Verification

Bluesky Custom Domain DID DNS Generator

Generate bulletproof DNS TXT records for your custom domain, resolve your permanent DID identifier, and verify live DNS propagation across Cloudflare, Namecheap, and GoDaddy.

01. Bluesky Account & DID

@

Queries public ATProto API client-side to fetch your cryptographic DID.

PLC Formatted

02. Desired Custom Domain

Enter your apex domain (e.g. alice.com) or subdomain (e.g. news.org).

Generated DNS Record
Cloudflare Format
Type: TXT
Name / Host: _atproto
Value / Content: did=did:plc:z72i7hdynmk6r22z27h6tvur
TTL: Auto (or 60 seconds)
In Cloudflare, enter _atproto in the Name field. Cloudflare automatically handles root domain mapping.

Live DNS Propagation Verifier

Test if your TXT record is visible globally via Google DNS-over-HTTPS (DoH)

Ready to query global DNS...
_atproto.mywebsite.com
Method 2 Alternative: HTTP Well-Known File (.well-known/atproto-did) ↓

If you have web hosting and prefer not to edit DNS, create a public static file at:

https://mywebsite.com/.well-known/atproto-did

File contents (plain text, single line):

did:plc:z72i7hdynmk6r22z27h6tvur
// VERIFICATION PROTOCOL

How to Complete Verification Inside the Bluesky App

Follow these 4 steps once your DNS record is live.

1

Go to Settings

Open Bluesky → Settings → Account → Handle → tap "I have my own domain".

2

Enter Your Domain

Type your exact domain (e.g. alice.com) and select the "DNS Panel" verification tab.

3

Add DNS TXT Record

Paste the generated TXT record into your DNS provider and run our Live Test button above to confirm propagation.

4

Click Verify

Tap "Verify DNS Record" in Bluesky. Your profile instantly converts to your verified custom handle!

// FAQ

Frequently Asked Questions

Common issues and solutions for Bluesky domain verification.

What happens to my followers and posts when I switch to a custom domain? ↓
Nothing is lost! Because the AT Protocol decouples your user identity (your permanent DID cryptographic string) from your human-readable handle, all your followers, follows, posts, likes, and lists remain 100% intact. Mentions of your old handle will redirect seamlessly to your custom domain.
What is the double domain error on Namecheap and GoDaddy? ↓
Many registrars automatically append your domain name to whatever you type in the "Host" field. If you enter _atproto.yourdomain.com in Namecheap, Namecheap saves it as _atproto.yourdomain.com.yourdomain.com. This breaks verification. On Namecheap and GoDaddy, only enter _atproto in the Host field!
How do I use a subdomain (e.g., @press.brand.com)? ↓
For subdomains, the Host name must include the subdomain slug. For example, for press.brand.com, the Host field in Cloudflare must be _atproto.press. The Value field remains identical (did=did:plc:...).
Does setting up a custom handle cost money? ↓
No! Bluesky custom domain verification is 100% free. You only pay standard domain registration fees to your chosen domain registrar (e.g. $10/year for a .com). Bluesky charges zero verification or subscription fees.

Understanding the AT Protocol Identity Architecture

The Authenticated Transfer Protocol (ATProto) powers Bluesky and differs fundamentally from traditional federated networks like Mastodon (ActivityPub) or centralized platforms like Twitter/X. On legacy networks, your handle is your identity. If you change your domain or the server shuts down, you lose your social graph.

1. Decentralized Identifier (DID)

A permanent, cryptographic string (e.g., did:plc:z72i7hdynmk6r22z27h6tvur) that anchors your cryptographic keypairs, user data repository, and public signing keys. Even if you change your domain handle 10 times, your DID never changes.

2. Human-Readable Handle

Your custom domain (e.g., alice.com) acts as a human-friendly pointer to your DID. When someone searches for your handle, Bluesky queries DNS TXT records to confirm your domain points back to your specific DID.

Common Troubleshooting & Verification Pitfalls