Identification
Its full user-agent string, exactly as it arrives at the gate:
Meta does not publish a way to verify facebookexternalhit's traffic. Treat its user agent as a claim, not proof: anyone can send it. Read Meta's documentation.
How to block facebookexternalhit
Add these two lines to the robots.txt file at the root of your site. Well-behaved crawlers read it before they crawl, so the change applies from facebookexternalhit's next visit. Nothing else on your site needs to change.
# Block facebookexternalhit from the whole site User-agent: facebookexternalhit Disallow: /
Blocking it breaks link previews on Meta apps. Meta says it may skip robots.txt for security and integrity checks.
Or let it visit but keep it away from part of the site:
# Let it in, but keep it out of one room User-agent: facebookexternalhit Allow: / Disallow: /members/
Observed behaviour
Nothing on record in the last 30 days.
Requested 0 disallowed pages out of 0 requests. Never read robots.txt.
Has never followed the hidden link to /trap/. Either well trained or very lucky.
Where it comes from
The networks facebookexternalhit's visits came from:
Nothing on record in the last 30 days.
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Questions site owners ask
Does facebookexternalhit respect robots.txt?
We can't say yet. It has not fetched robots.txt here, and it has not touched a disallowed page either.
Will blocking facebookexternalhit hurt my search rankings?
No. But links to your site will be shared without a title or preview image, which tends to get fewer clicks.
How often does facebookexternalhit visit?
Here, about 0 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.