Overview
HSTS preload bot is a security scanner from Chromium used for security scanning, malware checks, vulnerability assessment, certificate review, and site-safety analysis.
Its primary user-agent pattern is hstspreload-bot.
HSTS preload bot is Unverified at the identity-evidence level. The listed identity remains useful for detection, but this record does not currently contain authoritative evidence sufficient to authenticate the identity claim.
Robots.txt behavior is not currently confirmed.
HSTS preload bot should be reviewed against site policy, source evidence, crawl rate, and requested paths before a permanent allow or block rule is created.
Identity
- User-Agent
hstspreload-bot- HTTP Agent Examples
hstspreload-bot- Robots.txt Token
hstspreload-bot- Identity Type
- Observed
- Evidence Method
- Treat `hstspreload-bot` as an identity signal only. Confirm it with current operator documentation, cryptographic verification, forward-confirmed reverse DNS, source-network ownership, or other authoritative evidence before trusting the claimed identity.
Classification
- Type
- Security
- Kind
- Scanner
- Family
- Chromium
- Purpose
- security
Behavior and handling
- Common Use
- HSTS preload bot is used for security scanning, malware checks, vulnerability assessment, certificate review, and site-safety analysis.
- Detection Notes
- HSTS preload bot traffic is primarily detected by the `hstspreload-bot` user-agent pattern. Compare source IPs, reverse DNS, request paths, and crawl cadence with Chromium infrastructure before trusting the traffic.
- Respects robots.txt
- Unknown
- Spoofing Risk
- HSTS preload bot has medium spoofing risk because user-agent strings can be copied; pair the match with DNS, IP, behavior, or operator evidence.
- Risk
- Neutral
- Recommended Handling
- Depends
Rules and controls
- Robots.txt Snippet
# robots.txt behavior is unconfirmed. Do not rely on this rule without verification.