Free tool

Is this really GPTBot?

Paste an address from your logs and the User-Agent it sent. This checks the claim against the address list OpenAI publishes, and tells you whether the request really came from them.

GPTBot collects content used to train OpenAI models. Sites that decide to allow or block it need to know the traffic actually came from OpenAI, and a growing number of scrapers borrow the name.

Paste the whole line from your log. The claim is what gets checked.

No account, and nothing is stored against you. We look the address up, we do not log who asked.

What the three answers mean

Verified

The address is inside the list OpenAI publishes for GPTBot, or it reverse resolves into their own zone and that hostname resolves back to the same address. This is a positive result, not an absence of evidence.

Forged

OpenAI publishes the complete list of addresses GPTBot crawls from, and this address is not in it. Something sent you the name without the infrastructure behind it.

Cannot tell

We hold no authoritative answer for this one, so we say so rather than guessing. A missing reverse DNS record is suspicious and it is not proof, and a checker that turns "I do not know" into "forged" is worse than useless: it is confidently wrong.

How OpenAI says to verify GPTBot

OpenAI publishes the address ranges GPTBot crawls from as a JSON file, refreshed as their infrastructure changes.

We refresh our copy of that list every twelve hours. If ours goes stale, this tool returns "cannot tell" and says so, rather than condemning a crawler that added addresses since we last looked. Read the source: OpenAI's documentation.

Questions

How do I verify GPTBot?

Compare the address against the range list OpenAI publishes. Unlike Google, OpenAI does not document a reverse DNS procedure for GPTBot, so the published ranges are the authoritative check. This page compares against a copy refreshed every twelve hours.

What is the difference between GPTBot, OAI-SearchBot and ChatGPT-User?

GPTBot collects content that may be used to train models. OAI-SearchBot builds the index behind ChatGPT search results. ChatGPT-User fetches a page because a person asked ChatGPT about it right then. They are separate agents with separate published address lists, and robots.txt can allow or refuse each independently.

Does blocking GPTBot stop ChatGPT citing my site?

Not necessarily. Blocking GPTBot removes your content from training data. Blocking OAI-SearchBot is what removes you from the search index behind ChatGPT answers, and refusing ChatGPT-User stops the live fetch when a user asks about your page. Those are three different decisions, and most sites want different answers to them.

One address is not the question

You came here with a log line. If something is forging GPTBot against your site, it is not doing it once, and checking them one at a time is not a plan. WebDecoy watches every request that claims a crawler identity, verifies each one the way this page just did, and links the ones that come back to the same actor even when the addresses keep changing.

See what is claiming to be a crawler on your site

Ready to protect your site?

Talk to our team about your bot protection needs.

Contact Sales