Identification
Its full user-agent string, exactly as it arrives at the gate:
This is not a real species. It is a costume: requests that use GPTBot's name but fail reverse-DNS or IP-range checks against OpenAI's network.
How to block GPTBot (impostor)
GPTBot (impostor) does not read robots.txt, so a polite sign is wasted on it. Refuse it at your web server or firewall instead. User agents are easy to fake, so pair this with rate limiting.
# robots.txt will not stop GPTBot (impostor). Block it at the server.
# nginx
if ($http_user_agent ~* "GPTBot") {
return 403;
}The same thing on Apache:
# Apache (.htaccess)
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} GPTBot [NC]
RewriteRule .* - [F,L]Observed behaviour
Nothing on record in the last 30 days.
Requested 0 disallowed pages out of 18 requests. Read robots.txt 3 times.
Has never followed the hidden link to /trap/. Either well trained or very lucky.
Where it comes from
Claims to be GPTBot. Real GPTBot traffic comes from OpenAI's own network; these visits came from:
Nothing on record in the last 30 days.
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Keeper's field notes
Questions site owners ask
Does GPTBot (impostor) respect robots.txt?
Yes. In 18 requests observed here it has read robots.txt and never fetched a disallowed page.
Will blocking GPTBot (impostor) hurt my search rankings?
No. Nothing respectable will miss it.
How often does GPTBot (impostor) visit?
Here, about 3 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.