Identification
Its full user-agent string, exactly as it arrives at the gate:
This is not a real species. It is a costume: requests that use ChatGPT-User's name but fail reverse-DNS or IP-range checks against OpenAI's network.
How to block ChatGPT-User (impostor)
ChatGPT-User (impostor) does not read robots.txt, so a polite sign is wasted on it. Refuse it at your web server or firewall instead. User agents are easy to fake, so pair this with rate limiting.
# robots.txt will not stop ChatGPT-User (impostor). Block it at the server.
# nginx
if ($http_user_agent ~* "ChatGPT-User") {
return 403;
}The same thing on Apache:
# Apache (.htaccess)
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} ChatGPT-User [NC]
RewriteRule .* - [F,L]Observed behaviour
Nothing on record in the last 30 days.
Requested 0 disallowed pages out of 0 requests. Never read robots.txt.
Has never followed the hidden link to /trap/. Either well trained or very lucky.
Where it comes from
Claims to be ChatGPT-User. Real ChatGPT-User traffic comes from OpenAI's own network; these visits came from:
Nothing on record in the last 30 days.
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Questions site owners ask
Does ChatGPT-User (impostor) respect robots.txt?
We can't say yet. It has not fetched robots.txt here, and it has not touched a disallowed page either.
Will blocking ChatGPT-User (impostor) hurt my search rankings?
No. Nothing respectable will miss it.
How often does ChatGPT-User (impostor) visit?
Here, about 0 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.