Identification
Its full user-agent string, exactly as it arrives at the gate:
There is no operator to verify against. This name is what software calls itself when nobody gave it one.
How to block Go-http-client
Go-http-client does not read robots.txt, so a polite sign is wasted on it. Refuse it at your web server or firewall instead. User agents are easy to fake, so pair this with rate limiting.
# robots.txt will not stop Go-http-client. Block it at the server.
# nginx
if ($http_user_agent ~* "Go-http-client") {
return 403;
}The same thing on Apache:
# Apache (.htaccess)
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} Go-http-client [NC]
RewriteRule .* - [F,L]Observed behaviour
Most active around 06:00. Before the coffee is made.
Requested 0 disallowed pages out of 45 requests. Never read robots.txt.
Has never followed the hidden link to /trap/. Either well trained or very lucky.
Where it comes from
Scripts and scanners run from wherever their owners rent a server. These are the networks behind the visits on file:
Networks and countries come from the visitor's IP address, looked up in a local copy of the DB-IP database. The addresses themselves are never stored.
Keeper's field notes
Questions site owners ask
Does Go-http-client respect robots.txt?
We can't say yet. It has not fetched robots.txt here, and it has not touched a disallowed page either.
Will blocking Go-http-client hurt my search rankings?
No. Nothing respectable will miss it.
How often does Go-http-client visit?
Here, about 6 requests a day over the last week. Visits to your site depend on its size, how often it changes, and how many links point to it.