Short answer: “Invalid Handle” means Bluesky can no longer confirm that your domain points at your account. Usually the _atproto TXT record was deleted, the domain expired or DNS moved. Restore the record, then re-submit your handle in Settings → Account → Handle. Your posts and followers are safe.

Here is what the warning means, how to find the exact cause in a minute, and the fix for each case.

On this page:

The Direct Answer

Question Answer
Is my account broken or suspended? No – only the handle check is failing
Did I lose posts or followers? No – they belong to your DID, which is unchanged
Most common cause? The _atproto TXT record is missing or wrong
Second most common? The domain expired or moved to a new DNS provider
Quickest fix if I no longer own the domain? Switch to a .bsky.social handle
Can I see it on other people? Yes – and it means the same thing for them

What “Invalid Handle” Means on Bluesky

A Bluesky handle is a domain name, and it is checked in both directions. Your account's identity document (tied to your DID, the permanent ID that starts with did:plc:) says “my handle is yourdomain.com”. And yourdomain.com has to say back “I belong to this DID”, either with a TXT record at _atproto.yourdomain.com or with a file at https://yourdomain.com/.well-known/atproto-did.

When both sides match, apps show your handle. When the domain side stops answering, or answers with a different DID, apps can't trust the name, so they show ⚠ Invalid Handle in its place. That is a safety feature: without it, anyone could claim any domain as their handle.

Nothing else about your account changes. You can still post, people still follow you, and links that use your DID still work. For a refresher on how handles and DIDs fit together, see our custom domain handle guide and the ATProtocol architecture guide.

Why Your Bluesky Handle Became Invalid

  • The TXT record was deleted. Often by accident during a DNS clean-up, or when a website builder replaced all your records.
  • You moved DNS providers or nameservers. Records don't always come with you. A transfer from one registrar to another, or switching to Cloudflare, is the classic trigger.
  • The domain expired. When it lapses, the registrar stops serving your records, and every handle on that domain goes invalid.
  • The record has a typo or a missing prefix. The value must be did=did:plc:…. A host name of _atproto.yourdomain.com in a panel that adds the domain automatically creates the wrong name.
  • There are two _atproto records. If an old record for a different account is still there, the answer is ambiguous and the check fails.
  • The well-known file broke. With the file method, a site redesign, a redirect to www, an expired HTTPS certificate or an HTML error page in place of the plain text all cause failures.
  • A subdomain owner removed your record. If your handle is something like you.company.com, the company controls the record. Removing it is how organizations retire handles.

How to Check What's Wrong

Start by finding your DID. In Bluesky, the handle settings screen shows it when you choose your own domain, and your profile's data is also visible in tools like Skyscraper's Account Data. Then check the domain from outside.

If you used a DNS TXT record

dig TXT _atproto.yourdomain.com +short

You want exactly one line: "did=did:plc:yourdid". No output means the record is missing. Two lines mean there is a duplicate. A different DID means the record points at another account.

If you used the well-known file

curl -i https://yourdomain.com/.well-known/atproto-did

You want a 200 status and a body that is just your DID. A 301 or 302, a 404, a certificate error or a page of HTML are all failures.

Ask the network what it sees

Bluesky's public API will try to resolve a handle for you. Open this in a browser, with your domain in place of the example:

https://public.api.bsky.app/xrpc/com.atproto.identity.resolveHandle?handle=yourdomain.com

If it returns your DID, the domain side is fine and you only need to re-submit the handle so apps refresh. If it returns an error, the domain side is the problem.

How to Fix an Invalid Handle on Bluesky

  1. Check the record from outside. Run dig TXT _atproto.yourdomain.com +short (or the curl check for the file method) and confirm it returns your DID.
  2. Fix or restore the record. If it is missing or wrong, add the TXT record again with host _atproto and value did=did:plc:yourdid, and remove any second _atproto record pointing at another DID.
  3. Wait for DNS to publish. Give it a few minutes, longer if you just changed nameservers or DNS providers.
  4. Re-submit your handle. In Bluesky, go to Settings, then Account, then Handle, choose your own domain again, enter the same domain and verify. This asks the network to re-check your handle.
  5. Or switch back to a bsky.social handle. If you no longer control the domain, pick a new yourname.bsky.social handle in the same screen. The warning disappears as soon as the new handle is saved.

If DNS is correct and the warning persists after re-submitting, give it some time. Apps and the AppView cache identity information, and the refresh is not always instant. Avoid changing the record back and forth while you wait, because each change restarts the clock.

If your domain expired

Renew it as soon as you can; most registrars hold an expired domain for a grace period. After renewal, check that your DNS records came back, then re-submit the handle. If the domain is gone for good, switch to a .bsky.social handle. Your followers won't notice anything except the new name.

Prevent it from happening again

  • Turn on auto-renew for any domain you use as a handle.
  • Before moving DNS, write down the _atproto record and add it at the new provider before switching nameservers.
  • Prefer the TXT record over the file method; it survives website redesigns.
  • Keep a recent Account Backup so you have your DID and data on hand. See our backup guide.

Why Someone Else's Handle Shows as Invalid

The same thing has happened on their side: their domain no longer confirms their account. It usually means an expired domain or a broken DNS change, not anything sinister. Be a little more careful, though. An invalid handle means the name is not proven, so don't rely on it to tell you who the account belongs to. If an account that claims to be a public figure shows Invalid Handle, look for other signals such as a blue check or links from their official site, and report impersonation if you find it. Our moderation settings guide covers reporting and filters.

Frequently Asked Questions

What does Invalid Handle mean on Bluesky?

It means Bluesky can no longer confirm that the domain used as the handle points at that account. The account itself is fine; only the handle check is failing.

Will I lose my followers if my handle is invalid?

No. Followers, posts and likes are tied to your DID, which does not change. Fixing or changing the handle does not affect them.

How do I fix Invalid Handle on Bluesky?

Restore the _atproto TXT record (value did= followed by your DID) or the well-known file on your domain, wait for DNS to publish, then re-enter the same domain in Settings, Account, Handle and verify it.

Why did my Bluesky handle become invalid by itself?

The most common reasons are a deleted DNS record, a move to a new DNS provider that did not copy the record, or an expired domain.

How long does it take for an invalid handle to fix itself?

Usually minutes after the record is correct and the handle is re-submitted. Caching can make it take longer, so wait before changing the record again.

Can I go back to a bsky.social handle?

Yes. Choose a new handle in Settings, Account, Handle. The Invalid Handle warning goes away once the new handle is saved.

Handles in Skyscraper

Skyscraper shows the same handle status the network reports, so a handle that verifies on Bluesky verifies in Skyscraper too. Useful when you're troubleshooting:

  • Account Data – browse your repository and identity records, in lexicon or plain English
  • Multiple accounts – check how a handle looks from another signed-in account
  • Full HTML and JSON backup of your posts before you change anything

Download Skyscraper →