PerplexityBot: user agent, IP verification and robots.txt
PerplexityBot is operated by Perplexity. It is classified here as Search (Search index). Verification method: Published CIDR list.
Exact user-agent string
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)
robots.txt token: PerplexityBot. The user-agent string is self-asserted and can be
forged by anyone. It is a claim, not proof.
How to verify PerplexityBot is genuine
Match the source IP against Perplexity's published CIDR list: https://www.perplexity.com/perplexitybot.json
8 ranges published, as of 2025-02-07. Pulled live at build time, never hardcoded.
How to block or allow PerplexityBot
User-agent: PerplexityBot
Disallow: / Replace Disallow with Allow to permit it explicitly.
What blocking PerplexityBot costs you
Perplexity states PerplexityBot is what surfaces and links websites in Perplexity search results, and is not used to crawl content for AI foundation models. Blocking it removes you from Perplexity's results without buying you any training protection, because it was never a training crawler.
What is specific to PerplexityBot
PerplexityBot's published range is unusually small and almost entirely single-address /32 entries rather than blocks. That has a practical consequence: an allowlist built from this file is brittle, and a genuine PerplexityBot request from a newly added address will fail verification until the file is re-pulled. Perplexity's own documentation is also the only operator guidance in this set that walks through WAF configuration explicitly, including Cloudflare and AWS WAF, recommending a rule that requires both the user-agent and the IP set rather than either alone.
Verify a request claiming to be PerplexityBot
Check a PerplexityBot request against Perplexity's published ranges
Source
Primary documentation: https://docs.perplexity.ai/guides/bots. Last verified 2026-08-02.
Other Perplexity crawlers
- Perplexity-User - User-triggered fetch