Bot Verifier

Crawler lists updated 24 days ago.

Pick the bot the user-agent string claims — spoof detection only runs when there's a claim to test. Try it with a real one: — fills the form; press Verify to run the check (checks are rate-limited).

검사는 당사 서버에서 실행됩니다. 입력한 URL을 가져오지만 결과는 보관하지 않습니다. Submitted IPs are checked in memory, never stored. Anonymous aggregate verdict counts feed our research posts; domains are counted once via an anonymized hash, never stored in the clear. 익명 실행별 결과 계수는 종합 연구에 사용될 수 있습니다. URL, 도메인, IP 및 식별자는 절대 포함되지 않으며 100회 미만의 실행에 대한 통계는 공개하지 않습니다.

피드백
버그 신고

Bot Verifier에서 문제가 발생했나요? 무슨 일이 있었는지 알려 주세요. 신고는 공개 목록이 아니라 비공개 분류 대기열로 바로 전송됩니다.

전송될 정보
 도구 입력, 업로드, 붙여넣은 소스, 전체 결과, 쿼리 매개변수 또는 URL 조각은 자동으로 첨부되지 않습니다. 위에서 선택한 구절을 수정하거나 삭제할 수 있습니다. 브라우저 및 악용 방지 메타데이터는 스팸 방지를 위해 처리됩니다. 

Bulk IPs or access-log lines

Paste up to 500 IPs or log lines. Published-range matching and user-agent claim extraction run entirely in your browser. Use Spot-check only for the few rows where you want live reverse-DNS confirmation.

Supported bots and verification methods

Not every operator makes verification possible. Some publish IP ranges and support reverse DNS, some publish ranges only, and some publish nothing at all — a user agent alone proves nothing, since any script can send any user-agent string.

BotOperatorTypePublished IP listReverse DNS
Googlebot · docs Google Search ✅ 315 ranges ✅ .googlebot.com, .google.com
Google special crawlers · docs Google Search ✅ 270 ranges ✅ .google.com
Google user-triggered fetchers · docs Google User-triggered ✅ 1550 ranges ✅ .gae.googleusercontent.com, .google.com, .googleusercontent.com
Bingbot · docs Microsoft Search ✅ 28 ranges ✅ .search.msn.com
YandexBot · docs Yandex Search ❌ none ✅ .yandex.ru, .yandex.net, .yandex.com
Baiduspider · docs Baidu Search ❌ none
Yeti · docs Naver Search ❌ none
GPTBot · docs OpenAI AI training ✅ 21 ranges
OAI-SearchBot · docs OpenAI AI search ✅ 35 ranges
ChatGPT-User · docs OpenAI User-triggered ✅ 258 ranges
ClaudeBot · docs Anthropic AI training ✅ 20 ranges
PerplexityBot · docs Perplexity AI search ✅ 8 ranges
Perplexity-User · docs Perplexity User-triggered ✅ 4 ranges
Applebot · docs Apple Search ✅ 12 ranges ✅ .applebot.apple.com
Amazonbot · docs Amazon AI training ❌ none ✅ .crawl.amazonbot.amazon
DuckDuckBot · docs DuckDuckGo Search ✅ 481 ranges
Meta-ExternalAgent · docs Meta AI training ❌ none
Bytespider ByteDance AI training ❌ none

How verification works

  1. Published-range check. The IP is matched against the operator's official IP range list (the same JSON files Google, Microsoft, OpenAI, Perplexity, Apple, and DuckDuckGo publish), refreshed weekly.
  2. Forward-confirmed reverse DNS (FCrDNS). For bots that support it, the IP's PTR record must resolve to an official hostname (e.g. crawl-66-249-66-1.googlebot.com) at a domain-label boundary, and a forward lookup of that hostname must answer the exact same IP. Both directions must agree — a PTR record alone is trivially fakeable.
  3. Naming the spoofer. When a claim fails both checks, the IP's actual network owner is looked up via its ASN, so the verdict says who it really is instead of just "not Googlebot."

The verdict tiers are deliberately distinct: reverse-DNS confirmed is proof; a published-list match is strong but not confirmation; and unverifiable bots such as Bytespider and Meta publish no machine-readable range list — treat those user agents with suspicion. ClaudeBot now has an official published list, so it can return a list match even though Anthropic does not document reverse-DNS verification.

Need evidence across many requests? Use the Log File Analyzer to inspect crawl budget by bot and section, status-code waste, and spoofing signals. Log parsing stays in your browser.

이 도구 정보

Googlebot, Bingbot, GPTBot, ClaudeBot 등 크롤러라고 주장하는 IP를 운영자가 공개한 IP 범위와 정방향 확인 역방향 DNS(FCrDNS)로 검증합니다. 스푸핑이 감지되면 실제 network owner와 복사 가능한 차단 규칙도 표시합니다.

IP는 메모리에서만 처리되고 저장되지 않으며 user-agent 문자열만으로 신원을 확인하지 않습니다.

기능

  • 공식 공개 CIDR 범위와 FCrDNS라는 두 독립적인 신원 검사
  • 확인 불가를 억지 실패로 바꾸지 않는 5가지 명시적 verdict
  • IPv4·IPv6 및 bulk 모드에서 최대 500개 IP 또는 log line 지원
  • 스푸핑 IP를 위한 Cloudflare WAF, nginx 및 Apache 차단 규칙 생성

작동 방식

user-agent가 아니라 서버 log의 IP를 사용합니다. IP가 공개 범위에 포함되는지 비교하고 PTR hostname을 역방향 조회한 뒤 그 hostname을 다시 정방향 조회합니다. 공식 domain 경계와 정확한 IP가 양방향으로 일치할 때만 신원을 확인합니다.

제한사항

  • 검증 품질은 운영자가 공개한 자료에 달려 있습니다. IP 범위나 reverse DNS 방법을 제공하지 않는 크롤러는 확인 불가로 남습니다.
  • Verified는 신원만 확인하며 의도나 안전성을 보장하지 않습니다. 실제 크롤러도 rate limit 또는 차단 대상이 될 수 있습니다.
  • 공식 범위 목록은 매주 갱신되므로 verdict는 며칠 전 snapshot을 반영할 수 있습니다.

자주 묻는 질문

실제 Googlebot인지 어떻게 확인하나요?

무엇이든 위조할 수 있는 사용자 에이전트 문자열이 아니라 서버 로그의 IP 주소를 가져와 두 가지 방법으로 확인하세요. Googlebot이 공개한 IP 범위와 대조하고, 순방향 확인이 포함된 역방향 도메인 이름 조회를 실행합니다. IP의 역방향 레코드는 googlebot.com 또는 google.com으로 끝나는 호스트 이름으로 확인되어야 하며, 그 호스트 이름을 순방향으로 조회했을 때 동일한 IP가 반환되어야 합니다. IP를 붙여 넣고 Googlebot을 선택하면 이 도구가 두 검사를 자동으로 수행합니다.

순방향 확인이 포함된 역방향 도메인 이름 조회란 무엇인가요?

양방향 이름 확인 검사입니다. 먼저 역방향 조회가 전용 레코드를 통해 IP를 호스트 이름으로 바꾸고, 이어서 그 호스트 이름을 순방향 조회했을 때 정확히 같은 IP로 돌아와야 합니다. 공식 도메인 경계에서 양방향이 모두 일치해야 합니다. IP 블록 소유자는 역방향 레코드를 임의 문자열로 설정할 수 있으므로 이것만으로는 아무것도 입증할 수 없고, 순방향 확인이 신뢰성을 제공합니다.

크롤러가 검증됨이나 위조됨 대신 검증 불가로 표시되는 이유는 무엇인가요?

Bytespider와 Meta의 크롤러를 포함한 일부 운영자는 IP 범위를 공개하거나 역방향 이름 확인을 지원하지 않으므로 주장에 대한 권위 있는 범위 또는 이름 확인 검사가 없습니다. 도구는 추측하지 않고 검증 불가를 반환합니다. Anthropic은 더 이상 이 범주에 속하지 않으며 공식 크롤러 IP 목록을 공개합니다. 일치 결과는 역방향 확인이 아니라 공개 목록 일치로 명확히 보고되고, 사용자 에이전트 문자열만으로는 여전히 위조할 수 있습니다.

가짜 크롤러를 IP로 차단할 수 있나요?

가능합니다. 위조 판정이 나오면 도구가 주요 에지 서비스와 웹 서버용 차단 규칙을 복사해 쓸 수 있게 제공합니다. 하지만 IP 하나를 막는 것은 반복 대응에 불과하며 위조자는 주소를 바꿉니다. 지속적인 가짜 크롤러 트래픽은 근거에 표시된 네트워크 소유자 기준으로 차단하거나 방화벽의 봇 관리 규칙을 사용하는 편이 더 효과적입니다.

여기서 IP를 확인하면 저장하거나 기록하나요?

아니요. 제출한 IP는 메모리에서 공개 범위 목록 및 실시간 DNS와 대조되며 어떤 저장소에도 기록되지 않습니다. 범위 목록은 운영자의 공식 출처에서 매주 갱신되므로 판정에는 최대 며칠 전의 범위가 반영됩니다.

다음 단계XML 사이트맵 생성기 — generate the corrected version. 안내는 영어로 제공됩니다.