Free tool

Is this really GPTBot?

Paste an address from your logs and the User-Agent it sent. This checks the claim against the address list OpenAI publishes, and tells you whether the request really came from them.

GPTBot collects content used to train OpenAI models. Sites that decide to allow or block it need to know the traffic actually came from OpenAI, and a growing number of scrapers borrow the name.

Paste the User-Agent value from your log. The claim is what gets checked.

Check up to 50 log lines with a free account

No account required. Shared links include the IP and User-Agent; results reflect the current verification data.

What the three answers mean

Verified

The address is inside the list OpenAI publishes for GPTBot, or it reverse resolves into their own zone and that hostname resolves back to the same address. This is a positive result, not an absence of evidence.

Forged

Fresh published ranges for this address family exclude the IP, or an authoritative DNS check identifies a different operator. The claimed name does not match the evidence.

Cannot tell

We hold no authoritative answer for this one, so we say so rather than guessing. A missing reverse DNS record is suspicious and it is not proof, and a checker that turns "I do not know" into "forged" is worse than useless: it is confidently wrong.

How OpenAI says to verify GPTBot

OpenAI publishes the address ranges GPTBot crawls from as a JSON file, refreshed as their infrastructure changes.

We refresh our copy of that list every twelve hours. If ours goes stale, this tool returns "cannot tell" and says so, rather than condemning a crawler that added addresses since we last looked. Read the source: OpenAI's documentation.

Questions

How do I verify GPTBot?

Compare the address against the range list OpenAI publishes. Unlike Google, OpenAI does not document a reverse DNS procedure for GPTBot, so the published ranges are the authoritative check. This page compares against a copy refreshed every twelve hours.

What is the difference between GPTBot, OAI-SearchBot and ChatGPT-User?

GPTBot collects content that may be used to train models. OAI-SearchBot builds the index behind ChatGPT search results. ChatGPT-User fetches a page because a person asked ChatGPT about it right then. They are separate agents with separate published address lists, and robots.txt can allow or refuse each independently.

Does blocking GPTBot stop ChatGPT citing my site?

Not necessarily. Disallowing GPTBot requests that future crawls exclude your content from potential training use; it does not remove existing training data. OAI-SearchBot controls search crawling. ChatGPT-User performs user-initiated fetches, for which robots.txt may not apply. Those are three different decisions, and most sites want different answers to them.

One address is not the question

You came here with a log line. If something is forging GPTBot against your site, it is not doing it once, and checking them one at a time is not a plan. WebDecoy watches every request that claims a crawler identity, verifies each one the way this page just did, and links the ones that come back to the same actor even when the addresses keep changing.

See what is claiming to be a crawler on your site

Ready to protect your site?

Talk to our team about your bot protection needs.

Contact Sales