Bingbot: robots token, verification and how to allow or disallow it
Bingbot is an AI crawler operated by Microsoft. Its robots.txt token is Bingbot, and the vendor documentation we fetched on 2026-09-06 is the source for every statement on this page.
| Robots token | Bingbot |
|---|---|
| Vendor | Microsoft |
| Purpose | search index |
| Documented verification | published IP ranges |
| Vendor documentation last verified | 2026-09-06 |
| Share of read domains disallowing it for / | 0.8% of 128 |
| Last verified |
Identity
| Robots token | Bingbot |
|---|---|
| Matched as | bingbot |
| Vendor | Microsoft |
| Purpose | search index |
| Documentation | https://www.bing.com/webmasters/help/which-crawlers-does-bing-use-8c184ec0 |
| Documented verification | published IP ranges: https://www.bing.com/toolbox/bingbot.json |
Included because Copilot answers ground on the Bing index. Microsoft also documents a reverse DNS verification tool; we assert only the range file that data/bot_ranges.json already carries (28 prefixes).
Allow or disallow it
User-agent: Bingbot Allow: /
User-agent: Bingbot Disallow: /
A robots.txt rule is a request that a well behaved crawler honours. It is not an access control, and this page does not tell anyone what to choose.
Questions
Does Bingbot obey robots.txt?
The vendor documentation at https://www.bing.com/webmasters/help/which-crawlers-does-bing-use-8c184ec0 states that Bingbot respects robots.txt. We fetched that page and it answered our checker on 2026-09-06. This records what the vendor documents, not what any individual request did.
How do I allow Bingbot in robots.txt?
Add this group to the robots.txt at the root of the host: User-agent: Bingbot Allow: /. The token is matched case insensitively as a substring of the user agent by RFC 9309, and the longest matching rule wins.
How do I disallow Bingbot in robots.txt?
Add this group to the robots.txt at the root of the host: User-agent: Bingbot Disallow: /. A robots.txt rule is a request that a well behaved crawler honours; it is not an access control.
How do I verify a request really came from Bingbot?
The vendor publishes the IP ranges this crawler fetches from at https://www.bing.com/toolbox/bingbot.json. Check the address of the request against that file. A user agent string on its own proves nothing, because anyone can send one.
What we measure
Of the 128 seeded domains whose robots.txt we have read, 1 disallow Bingbot for / and 127 allow it, which is 0.8% disallowed, week 2026-W37. Counts only: no domain is named.
The weekly AI crawler access index
Sources
| Source | Type | HTTP | Verified | Note |
|---|---|---|---|---|
| https://www.bing.com/webmasters/help/which-crawlers-does-bing-use-8c184ec0 | vendor | 200 | 2026-09-06 | 40 occurrences of bingbot in the fetched body |
| https://www.bing.com/toolbox/bingbot.json | vendor | 200 | 2026-09-06 | published IP ranges; fetched 200 on 2026-09-06 and refreshed weekly by scripts/refresh_bot_ranges.py (28 prefixes on disk) |
Free data
Check a domain against every token
AEO Watch is an independent, factual monitor. It is not affiliated with, endorsed by or speaking for any crawler vendor. Every statement is an observation with the date it was made and the raw evidence behind it: a robots.txt line, an HTTP status code, a header. There are no scores, no grades and no verdicts here, and nothing on this page is advice. A site opts out at any time and the opt out is honoured automatically and permanently.