Bot observatory · updated hourly

1,370,574 requests were refused in the last 24 hours

Everything automated that reaches our sites, what we let through, and what we turn away: by site, by network, and by name. Also the incidents, including the ones that were our fault, and what it all costs. Read the incidents · How this is measured

1,370,574
Refused in the last 24 hours
exact, from the firewall stream
47%
Of all requests
allowed traffic is a 10% sample, scaled
21,177
Networks seen this week
autonomous systems, by source address
16
Sites watched
every production host in the constellation

Every day since the drain went live

refused allowed (est.)
2026-08-192026-09-03

By site

Refused counts are exact. Request totals include allowed traffic scaled from a 10% sample, marked with a tilde.

SiteRequests, 7 daysRefusedShareRefused, 24 h
aboutus.com~32,550,9549,679,79430%1,350,691
dns.pizza~1,283,71236,3922.8%1,469
time.io~1,121,39162,0915.5%15,019
the.com~671,1621,6420.2%1
par.is~223,1678,5773.8%3,388
lodo.com~88,44000.0%0
how.is~46,29000.0%0
ayd.yoga~40,64000.0%0
ashtanga.yoga~9,95000.0%0
northhavenhousing.org~3,73770.2%0
overheard.com~1,702422.5%6
sailorsbakery.com~1,55000.0%0
bathm.at~1,06000.0%0
word.io~90110.1%0
untaken.zone~70000.0%0
mushk.in~50330.6%0

By name

Crawlers that announce themselves, grouped by what they are for, with the policy our firewall states for each. The share refused shows whether the policy is holding. Per address-hour is requests per source address per hour: a fleet on rented addresses sits near 1.

AI crawlers
~1,476,284 · 20 families
Search engines
~2,444,795 · 17 families
SEO crawlers
~137,471 · 13 families
Scripts & headless browsers
~1,130,509 · 22 families
Internet scanners
~517 · 8 families
Link previews
~79,840 · 14 families
Archives & research
~25,808 · 5 families
Monitors
~65,956 · 5 families
Other self-declared bots
~378,911 · 497 families
No user-agent
~4,687 · 1 family
Browser user-agents
~29,652,111 · 1 family
BotKindOur policyRequests, 7 daysRefusedNetworksPer address-hour
Bingbot
aboutus.com · ashtanga.yoga · ayd.yoga · bathm.at +9
Search enginesNo rule~1,984,6040.0%130.6
Node.js (fetch/undici)
aboutus.com · ayd.yoga · dns.pizza · how.is +3
Scripts & headless browsersNo rule~1,086,6780.5%1320.2
YandexBot impostor (wrong network)
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +5
impostorVaries by site~618,64899%416
GoogleOther
aboutus.com · ashtanga.yoga · ayd.yoga · the.com
AI crawlersNo rule~421,2900.0%131.7
ClaudeBot
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +7
AI crawlersChallenged~376,0680.5%233.1
ExaSearchBot
aboutus.com · dns.pizza · the.com · time.io
AI crawlersNo rule~333,497100%211.2
Googlebot
aboutus.com · ashtanga.yoga · ayd.yoga · bathm.at +12
Search enginesNo rule~207,2560.0%27.9
serankingbacklinksbot
aboutus.com
Other self-declared botsDenied~120,613100%11048.8
Applebot
aboutus.com · ashtanga.yoga · dns.pizza · par.is +3
Search enginesNo rule~112,5700.0%11.1
Amazonbot
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +7
AI crawlersChallenged~102,4077.9%11.1
Baiduspider
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +5
Search enginesChallenged~92,18778%32.2
Meta-ExternalAgent
ashtanga.yoga · ayd.yoga · lodo.com · the.com +1
AI crawlersDenied~76,88438%12
Unrecognised user-agent
aboutus.com · ashtanga.yoga · ayd.yoga · bathm.at +11
Other self-declared botsNo rule~75,1064.1%4443
SemrushBot
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +2
SEO crawlersDenied~72,77995%27.3
Bytespider (ByteDance)
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +3
AI crawlersChallenged~64,68562%61.6
facebookexternalhit
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +8
Link previewsNo rule~60,6100.0%11.1
Vercel internal
the.com
MonitorsNo rule~60,1900.0%22.2
SleepBot
aboutus.com · ashtanga.yoga · par.is · the.com +1
SEO crawlersDenied~33,98640%22.6
DuckAssistBot
aboutus.com · ayd.yoga · dns.pizza · par.is +2
AI crawlersNo rule~32,4600.0%17.9
PetalBot (Huawei)
aboutus.com · ashtanga.yoga · ayd.yoga · the.com +1
Search enginesChallenged~30,8820.8%11.7
wordpress
aboutus.com · the.com
Other self-declared botsNo rule~30,1890.0%7189.2
reflectionbot
aboutus.com · ayd.yoga · dns.pizza · the.com
Other self-declared botsNo rule~29,19859%12.8
Turnitin
aboutus.com · dns.pizza
Archives & researchNo rule~24,350100%1735.7
daum
aboutus.com
Other self-declared botsNo rule~24,006100%1461.7
shapbot
aboutus.com · ashtanga.yoga · dns.pizza · overheard.com +3
Other self-declared botsNo rule~19,8610.1%12.2
GPTBot
aboutus.com · ashtanga.yoga · ayd.yoga · lodo.com +7
AI crawlersChallenged~16,67714%46.5
Python (requests/httpx/aiohttp)
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +7
Scripts & headless browsersNo rule~16,43985%9323
WhatsApp
aboutus.com · how.is · par.is · the.com +1
Link previewsNo rule~15,3130.0%3621.1
facebookexternalhit impostor (wrong network)
aboutus.com · ashtanga.yoga · ayd.yoga · how.is +4
impostorNo rule~14,0240.7%2301.2
Meta-WebIndexer
aboutus.com · ayd.yoga · dns.pizza · how.is +3
AI crawlersChallenged~13,71295%11.3
OAI-SearchBot
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +8
AI crawlersNo rule~12,9920.0%31.6
DuckDuckBot impostor (wrong network)
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +5
impostorNo rule~11,4911.1%372
Barkrowler (Babbar)
aboutus.com · ayd.yoga · dns.pizza · par.is
SEO crawlersDenied~11,0160.1%12
ChatGPT-User
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +5
AI crawlersNo rule~10,8120.0%41.1
sentryuptimebot
dns.pizza
Other self-declared botsNo rule~9,9300.0%12.2
linkupbot
aboutus.com · the.com · time.io
Other self-declared botsNo rule~8,6442.6%119.4
HeadlessChrome
aboutus.com · ashtanga.yoga · ayd.yoga · dns.pizza +9
Scripts & headless browsersNo rule~8,3911.3%495.1
rednote-websearch-bot
aboutus.com · time.io
AI crawlersNo rule~8,145100%15.5
Electron
aboutus.com · time.io
Scripts & headless browsersNo rule~7,540100%2672.5
dns.pizza
aboutus.com · ayd.yoga · dns.pizza · how.is
Other self-declared botsNo rule~7,1700.0%41.2

By network

Where the requests come from, by autonomous system. A residential ISP with real customers shows several requests per address per hour and is mostly allowed. A cloud or hosting network sending browser-shaped requests at one per address per hour is a fleet, and gets challenged.

NetworkRequests, 7 daysRefusedPer address-hourMostlySites
COMCAST-7922
AS7922
~4,841,0081.2%4.9browser user-agentaboutus.com, ayd.yoga, dns.pizza +6
BYTEPLUS-AS-AP Byteplus Pte. Ltd.
AS150436
~2,992,019100%13.6browser user-agentaboutus.com, time.io
RCN-AS
AS6079
~2,964,6970.8%5.7browser user-agentaboutus.com, ayd.yoga, dns.pizza +4
ZEN-NET
AS4229
~2,930,902100%13.7browser user-agentaboutus.com
MICROSOFT-CORP-MSN-AS-BLOCK
AS8075
~2,116,0520.7%17.5Bingbotaboutus.com, ashtanga.yoga, ayd.yoga +15
BT-UK-AS BTnet UK Regional network
AS2856
~1,945,5431.3%3.7browser user-agentaboutus.com, ashtanga.yoga, dns.pizza +5
LUMEN-LEGACY-L3-CUSTOMER-SHARED-USE
AS10753
~1,558,9462.9%2browser user-agentaboutus.com, dns.pizza, par.is +2
GTT-BACKBONE GTT
AS3257
~1,294,26411%4.7browser user-agentaboutus.com, ashtanga.yoga, dns.pizza +3
AMAZON-AES
AS14618
~1,247,5801.0%5.6Node.js (fetch/undici)aboutus.com, ashtanga.yoga, ayd.yoga +14
AS-WAVE-1
AS11404
~1,185,5832.1%2.3browser user-agentaboutus.com, ashtanga.yoga, dns.pizza +2
OSL-188
AS398781
~832,7073.1%4.3browser user-agentaboutus.com, dns.pizza, time.io
COMCAST-33287
AS33287
~775,4500.9%5.4browser user-agentaboutus.com, dns.pizza, lodo.com +2
GOOGLE
AS15169
~642,4520.1%12GoogleOtheraboutus.com, ashtanga.yoga, ayd.yoga +13
TELETECH
AS208398
~618,58599%16.1YandexBot impostor (wrong network)aboutus.com, ashtanga.yoga, ayd.yoga +6
UUNET
AS701
~568,4992.5%3.1browser user-agentaboutus.com, ashtanga.yoga, ayd.yoga +7
AMAZON-02
AS16509
~500,3177.8%3.4ClaudeBotaboutus.com, ashtanga.yoga, ayd.yoga +12
BITE-US
AS210906
~431,16811%4.7browser user-agentaboutus.com, ashtanga.yoga, dns.pizza +2
T-MOBILE-AS21928
AS21928
~259,1297.4%2.8browser user-agentaboutus.com, ashtanga.yoga, ayd.yoga +7
ASN-CXA-ALL-CCI-22773-RDC
AS22773
~253,9836.0%2.7browser user-agentaboutus.com, ashtanga.yoga, ayd.yoga +5
CHARTER-20115
AS20115
~246,7235.2%2.8browser user-agentaboutus.com, ashtanga.yoga, ayd.yoga +5
TWC-10796-MIDWEST
AS10796
~184,6265.0%2.9browser user-agentaboutus.com, ashtanga.yoga, dns.pizza +5
TWC-11426-CAROLINAS
AS11426
~173,0964.2%3.1browser user-agentaboutus.com, ayd.yoga, dns.pizza +4
HETZNER-AS
AS24940
~162,15677%50.6serankingbacklinksbotaboutus.com, ashtanga.yoga, ayd.yoga +11
ATT-INTERNET4
AS7018
~158,9689.5%1.9browser user-agentaboutus.com, ashtanga.yoga, ayd.yoga +7
FACEBOOK
AS32934
~154,28328%1.6Meta-ExternalAgentaboutus.com, ashtanga.yoga, ayd.yoga +9
CABLE-NET-1
AS6128
~149,0673.0%3browser user-agentaboutus.com, dns.pizza, how.is +4
FRONTIER-FRTR
AS5650
~147,4604.8%2.7browser user-agentaboutus.com, dns.pizza, how.is +4
GOOGLE-CLOUD-PLATFORM
AS396982
~137,93538%3.2browser user-agentaboutus.com, ashtanga.yoga, ayd.yoga +12
CELLCO-PART
AS6167
~132,2673.9%2.7browser user-agentaboutus.com, ashtanga.yoga, ayd.yoga +8
TWC-20001-PACWEST
AS20001
~125,4989.7%2.7browser user-agentaboutus.com, ayd.yoga, dns.pizza +3

Incidents

What actually happened, dated, newest first. The ones marked as our mistake are here because a firewall that blocks people is a worse problem than any scraper.

  1. ·Abusive traffic·time.io

    Tencent cloud addresses rate-limited on time.io

    A burst from Tencent's cloud network (AS132203) hit time.io's pages at a rate no person browses at. The warden's proposal was applied through its normal pipeline: 60 requests per minute per address on that network, six-hour expiry.

    Verified afterwards with a real browser: time.io still answered 200 to a person. That check is the whole point of the pipeline.

  2. ·Policy·aboutus.com, dns.pizza, time.io, the.com, par.is

    Sixty-one percent of everything is denied, and it still bills

    Reading the August invoice: about 1.5 million requests a day across the constellation, 61% of them bots we refuse. A denied request still counts as an edge request, an observability event and, when it is rate-limited, a rate-limit charge.

    Web Analytics had grown 244% in a month. On aboutus.com, 98,000 "visitors" viewing 5.5 pages each were crawlers that execute JavaScript, so they show up as people in the analytics.

    Blocking is not free. The cheapest bot is the one that never gets a response, which is why the observatory tracks cost, not just counts.

  3. ·Our mistake·the.com, aboutus.com

    We blocked 3,864 real people in a day and nobody knew

    the.com had a 100-per-minute rate limit keyed on the TLS fingerprint (JA4). Every user of one browser build shares one fingerprint, so desktop Chrome worldwide was a single bucket. A second rule capped page requests at 30 per minute per address, and one page load is about eight requests.

    Measured from the log drain: 3,864 people received a 429 in 24 hours, from 229 networks over the week. The same night aboutus.com was returning 403 to Chrome 151 users on a consumer-VPN provider's exits, including someone on the pricing page.

    Both rules were loosened the moment it was seen. An hourly check now pages if a deny or rate-limit ever lands on a fingerprint that real browsers use.

    Never key a rate limit on a TLS fingerprint below thousands per minute. Never go under 120 per minute per address on paths a browser loads. Firewalls that stop people cost more than any scraper.

  4. ·Blind spot·time.io

    The alarm that fired 37 times for the rule working

    A new check paged 37 times in two hours, at high priority, because Meta's AI crawler (meta-externalagent) was being denied on time.io. That deny was the rule doing precisely its job.

    The fix was to publish intent: the warden now reads the live firewall rules and tells the watcher which crawlers are blocked on purpose. A deny that a live rule explains is not a page. Identity is now the network and the user-agent together, because one cloud (AS8075) is Microsoft's Bingbot and also every Azure tenant running GPTBot.

    An alarm that fires on intended behaviour is how the alarm for unintended behaviour gets ignored.

  5. ·Blind spot·aboutus.com, dns.pizza, time.io

    Moving off the metrics API to a log drain

    Vercel caps observability metrics queries at roughly 500 a day per team. The traffic watch hit it on 2026-08-15 and went blind. Support confirmed the cap is fixed on the Pro plan.

    Since 2026-08-19 every request to every site is delivered as a log drain to a small box that rolls it up hourly. The firewall stream is delivered in full; the rest is sampled at 10%. That box is what this page reads.

  6. ·Abusive traffic·aboutus.com

    The fleets that pretend to be desktop Chrome

    The largest thing in the logs is not a named crawler. It is millions of requests a week wearing a stock desktop-Chrome user-agent, arriving from cloud and hosting networks (ByteDance's BytePlus and ZEN-NET each send about three million a week), with roughly one request per address per hour.

    A person makes several requests from one address in an hour. A rented fleet makes one from each of thousands. The per-address rate is the tell, and it separates a fleet from a residential ISP whose customers are real.

    These get a challenge rather than a deny: a real browser solves it, and the fleet does not.

  7. ·Abusive traffic·aboutus.com, dns.pizza

    A crawler load turned into 66,000 partner-API errors

    aboutus.com renders six dns.pizza partner-API panels on every profile page. Under crawler load that fan-out became a sustained 3 to 5% error rate on the partner API, and 66,000 502s before anyone saw it. The API's own response-code distribution was not being watched.

    Fixed on both sides: a circuit breaker in aboutus.com so a wobble cannot become a stampede, and hourly response-code buckets on the partner API with a watchdog.

  8. ·Abusive traffic·aboutus.com, dns.pizza

    Crawler page views exhausted a 250,000-a-day quota by breakfast

    With 1.7 million profile pages and six panel calls per view, crawlers walking aboutus.com used the entire daily partner quota by 09:40 UTC, and the panels went dark for everyone else for the rest of the day.

    The quota was raised to a backstop that only abuse could reach. Quotas between our own properties are there to catch a runaway, not to ration a product.

What bots cost

A refused request is not free: it is billed as an edge request and an observability event before the firewall decides.

$127
of a $711 August 2026 bill attributable to refused traffic
34%
of requests refused over the last 16 days, the share used to split the traffic lines
$3.4
per million refused requests, at ~1,245,994 a day
Invoice lineBilledTo botsWhy
Observability events$220$75Every request, refused or not, is an event.
Vercel Agent (code review)$130Not traffic. Turned off on 2026-08-31.
Fluid compute (CPU + memory)$123A refused request never reaches a function. Allowed crawlers do, but that share is not attributed here.
Edge requests$71$24Billed before the firewall decides.
ISR writes$54Page regeneration; driven partly by allowed crawlers, not attributed here.
Firewall rate-limit evaluations$28$28Only exists because of the fleets. Up 121% month on month.
Web Analytics$21Up 244%: JavaScript-executing crawlers count as visitors. Not attributed here because they were allowed.

Lines are from the Vercel invoice for the cycle ending 2026-09-03. Traffic lines are split by the refused share measured here; the rate-limit line is attributed in full. Compute, ISR and analytics driven by allowed crawlers are not counted, so this is a floor.

How this is measured

Every request to every site in the constellation is delivered by Vercel as a log drain to one small server that holds no credentials. The firewall stream (deny, challenge, rate-limit) is delivered in full, so every refused count on this page is exact. Everything else is head-sampled at 10% and scaled back up, so allowed totals are estimates and are marked with a tilde.

Networks come from the source address via the iptoasn.com table. Bot names come from the user-agent, matched against a substring table we maintain. A browser-shaped user-agent is exactly that: a fleet on rented addresses sends one too, so the network and the requests per address per hour are what separate people from fleets. Our stated policy per bot is read from the live firewall rules, not from a list that could drift.

Not published: client IP addresses (personal data, and one address on a carrier-grade NAT is a crowd), TLS fingerprints, and firewall rule names. The last two tell an operator exactly what to change. They are available to partners through the partner API.

Feed generated 2026-09-03 01:25:01 UTC, through hour 20260903-00. Coverage since 2026-08-19; named-bot table since 20260826. Policy snapshot 2026-09-03T00:35:32Z.

The public feed behind this page is at n1.snowc.one/public/bots.json. Partners get the deeper tier (TLS fingerprints, rule names, hourly series) through /api/partner/v1/bots. See also Newborn domains, the daily zone census.