Overview
Google Safety is a monitoring bot from Google used for security scanning, malware checks, vulnerability assessment, certificate review, and site-safety analysis.
Its primary user-agent pattern is Google-Safety.
Google Safety is verified with High confidence. The identity type is Verified Bot, and the evidence basis is official operator documentation.
Google Safety is marked as not reliably governed by robots.txt directives; use server-side rules if the traffic should be restricted.
Google Safety can usually be allowed after confirming the source and monitoring request volume.
Identity
- User-Agent Pattern
-
Google-Safety - HTTP Agent Examples
-
Google-Safety - Robots Token
- Google-Safety
- Identity Type
- Verified bot
- Evidence Method
- Verify Google Safety by matching `Google-Safety` to Google evidence, then checking reverse DNS, source-network ownership, signed request data, or published crawler documentation when available.
Classification
- Type
- Security
- Kind
- Crawler
- Family
- Purpose
- Abuse and malware detection
Behavior and handling
- Common Use
- Abuse-specific crawling, including malware discovery for publicly posted links on Google properties.
- Detection Notes
- Google Safety traffic is primarily detected by the `Google-Safety` user-agent pattern. Compare source IPs, reverse DNS, request paths, and crawl cadence with Google infrastructure before trusting the traffic.
- Respects robots.txt
- No
- Spoofing Risk
- Google Safety has medium spoofing risk because the user-agent can be copied, even when the bot has strong source or documentation support.
- Risk
- Safe
- Recommended Handling
- Do not block
Rules and controls
- Robots.txt Snippet
-
# This agent may ignore robots.txt. Use authenticated access controls or network policy when blocking is required.
Relationships
- Operator
- Google Checked 2026-08-07
Relationships without an Evidence link are normalized from the canonical directory record. They should not be interpreted as independent proof of physical presence or request origin.