Cookie Consent by Free Privacy Policy Generator Google-Safety User Agent - Google Bot Details | CL SEO

Google-Safety

Google • Web Crawler
Security May ignore robots.txt
#google #malware discovery #abuse checks

What is Google-Safety?

Google lists Google-Safety among its special-case crawlers and says it handles abuse-specific work, such as malware discovery for publicly posted links on Google properties. It is not Googlebot and does not index pages for ordinary Search results. Google states that this identity ignores robots.txt rules, so adding a Disallow group will not control these safety requests. Verify a suspicious claim with Google's published special-crawler IP ranges.

User Agent String

Google-Safety

How to Control Google-Safety

Block Completely

To prevent Google-Safety from accessing your entire website, add this to your robots.txt file:

# Block Google-Safety User-agent: Google-Safety Disallow: /

Block Specific Directories

To restrict access to certain parts of your site while allowing others:

User-agent: Google-Safety Disallow: /admin/ Disallow: /private/ Disallow: /wp-admin/ Allow: /public/

Set Crawl Delay

To slow down the crawl rate (note: not all bots respect this directive):

User-agent: Google-Safety Crawl-delay: 10

How to Verify Google-Safety

Verification Method:
Compare the source IP with Google's special-crawlers.json ranges or use Google's forward-confirmed reverse-DNS process.

Learn more in the official documentation.

Detection Patterns

Multiple ways to detect Google-Safety in your application:

Basic Pattern

/Google\-Safety/i

Strict Pattern

/^Google\-Safety$/

Flexible Pattern

/Google\-Safety[\s\/]?[\d\.]*?/i

Vendor Match

/.*Google.*Google\-Safety/i

Implementation Examples

// PHP Detection for Google-Safety function detect_google_safety() { $user_agent = $_SERVER['HTTP_USER_AGENT'] ?? ''; $pattern = '/Google\-Safety/i'; if (preg_match($pattern, $user_agent)) { // Log the detection error_log('Google-Safety detected from IP: ' . $_SERVER['REMOTE_ADDR']); // Set cache headers header('Cache-Control: public, max-age=3600'); header('X-Robots-Tag: noarchive'); // Optional: Serve cached version if (file_exists('cache/' . md5($_SERVER['REQUEST_URI']) . '.html')) { readfile('cache/' . md5($_SERVER['REQUEST_URI']) . '.html'); exit; } return true; } return false; }
# Python/Flask Detection for Google-Safety import re from flask import request, make_response def detect_google_safety(): user_agent = request.headers.get('User-Agent', '') pattern = r'Google\-Safety' if re.search(pattern, user_agent, re.IGNORECASE): # Create response with caching response = make_response() response.headers['Cache-Control'] = 'public, max-age=3600' response.headers['X-Robots-Tag'] = 'noarchive' return True return False # Django Middleware class google_safetyMiddleware: def __init__(self, get_response): self.get_response = get_response def __call__(self, request): if self.detect_bot(request): # Handle bot traffic pass return self.get_response(request)
// JavaScript/Node.js Detection for Google-Safety const express = require('express'); const app = express(); // Middleware to detect Google-Safety function detect_google_safety(req, res, next) { const userAgent = req.headers['user-agent'] || ''; const pattern = /Google\-Safety/i; if (pattern.test(userAgent)) { // Log bot detection console.log('Google-Safety detected from IP:', req.ip); // Set cache headers res.set({ 'Cache-Control': 'public, max-age=3600', 'X-Robots-Tag': 'noarchive' }); // Mark request as bot req.isBot = true; req.botName = 'Google-Safety'; } next(); } app.use(detect_google_safety);
# Apache .htaccess rules for Google-Safety # Block completely RewriteEngine On RewriteCond %{HTTP_USER_AGENT} Google\-Safety [NC] RewriteRule .* - [F,L] # Or redirect to a static version RewriteCond %{HTTP_USER_AGENT} Google\-Safety [NC] RewriteCond %{REQUEST_URI} !^/static/ RewriteRule ^(.*)$ /static/$1 [L] # Or set environment variable for PHP SetEnvIfNoCase User-Agent "Google\-Safety" is_bot=1 # Add cache headers for this bot <If "%{HTTP_USER_AGENT} =~ /Google\-Safety/i"> Header set Cache-Control "public, max-age=3600" Header set X-Robots-Tag "noarchive" </If>
# Nginx configuration for Google-Safety # Map user agent to variable map $http_user_agent $is_google_safety { default 0; ~*Google\-Safety 1; } server { # Block the bot completely if ($is_google_safety) { return 403; } # Or serve cached content location / { if ($is_google_safety) { root /var/www/cached; try_files $uri $uri.html $uri/index.html @backend; } try_files $uri @backend; } # Add headers for bot requests location @backend { if ($is_google_safety) { add_header Cache-Control "public, max-age=3600"; add_header X-Robots-Tag "noarchive"; } proxy_pass http://backend; } }

Should You Block This Bot?

Recommendations based on your website type:

Site Type Recommendation Reasoning
E-commerce Optional Evaluate based on bandwidth usage vs. benefits
Blog/News Allow Increases content reach and discoverability
SaaS Application Block No benefit for application interfaces; preserve resources
Documentation Selective Allow for public docs, block for internal docs
Corporate Site Limit Allow for public pages, block sensitive areas like intranets

Advanced robots.txt Configurations

E-commerce Site Configuration

User-agent: Google-Safety Crawl-delay: 5 Disallow: /cart/ Disallow: /checkout/ Disallow: /my-account/ Disallow: /api/ Disallow: /*?sort= Disallow: /*?filter= Disallow: /*&page= Allow: /products/ Allow: /categories/ Sitemap: https://example.com/sitemap.xml

Publishing/Blog Configuration

User-agent: Google-Safety Crawl-delay: 10 Disallow: /wp-admin/ Disallow: /drafts/ Disallow: /preview/ Disallow: /*?replytocom= Allow: /

SaaS/Application Configuration

User-agent: Google-Safety Disallow: /app/ Disallow: /api/ Disallow: /dashboard/ Disallow: /settings/ Allow: / Allow: /pricing/ Allow: /features/ Allow: /docs/

Quick Reference

User Agent Match

Google-Safety

Robots.txt Name

Google-Safety

Category

security

Respects robots.txt

May not respect

Quick Actions

Official Docs
Copied to clipboard!