Bingbot: user agent, IP verification and robots.txt
Bingbot is operated by Microsoft. It is classified here as Search (Search index). Verification method: Published CIDR list.
Exact user-agent string
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm) Chrome/W.X.Y.Z Safari/537.36
robots.txt token: bingbot. The user-agent string is self-asserted and can be
forged by anyone. It is a claim, not proof.
How to verify Bingbot is genuine
Match the source IP against Microsoft's published CIDR list: https://www.bing.com/toolbox/bingbot.json
28 ranges published, as of 2024-01-03. Pulled live at build time, never hardcoded.
How to block or allow Bingbot
User-agent: bingbot
Disallow: / Replace Disallow with Allow to permit it explicitly.
What blocking Bingbot costs you
Blocking bingbot removes you from Bing, and from the surfaces that draw on the Bing index rather than crawling independently, including Copilot. For most sites this is a larger loss than the Bing search share alone suggests.
What is specific to Bingbot
Bingbot's published range file has not been reissued in a long time. Its creationTime stamp is from January 2024, the oldest of any operator in this set by a wide margin, while OpenAI and Google refresh theirs within days. A stale published list is not the same as a wrong one, but it does mean a verification failure against bingbot.json is weaker evidence of spoofing than the same failure against a file republished last week. Microsoft also runs AdIdxBot on a separate token for Bing Ads quality checks, and its user-agent is close enough to bingbot's that log filters written loosely will catch both.
Verify a request claiming to be Bingbot
Check a Bingbot request against Microsoft's published ranges
Source
Primary documentation: https://www.bing.com/webmasters/help/which-crawlers-does-bing-use-8c184ec0. Last verified 2026-08-02.
Other Microsoft crawlers
- AdIdxBot - Bing Ads quality control