Log in
Sign up with Google

Monitoring bot · IBM Deutschland Research & Development GmbH

oBot is IBM Deutschland Research & Development GmbH’s monitoring bot

oBot is the web crawler of the Content Security Division of IBM Deutschland Research & Development GmbH. It categorizes web content for filtering databases.

Verifiable operator Respects robots.txt

Our take

Allow

Blocking it may lead to wrong or missing categories in web filters used by IBM customers.

User agent

Mozilla/5.0 (compatible; oBot/2.3.1; +http://www.xforce-security.com/crawler/)

01 · Operator

Who operates oBot

Official docs
xforce-security.com

02 · Behavior

What oBot does

oBot analyzes page content and assigns it to more than 65 categories. The results feed content filtering and security databases for IBM customers and OEM partners. The "o" comes from ONLY Solutions GmbH, the startup it originated from. IBM publishes the IPv4 and IPv6 ranges it crawls from.

03 · Impact

Why oBot matters for your site

If you allow it

  • Correct categorization keeps your site from being wrongly blocked by filters
  • Can be blocked via robots.txt

If you block it

  • No search traffic
  • Uses bandwidth for a commercial security product

04 · Allow

How to allow oBot

robots.txt

User-agent: oBot
Allow: /

Cloudflare

# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "oBot")
Action:     Skip › All Super Bot Fight Mode rules

# Also check Security › Bots: "Block AI bots" can block it regardless of robots.txt.

WordPress

# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: oBot
Allow: /

nginx

# nginx serves every user agent by default.
# Make sure no rule like this blocks it:
# if ($http_user_agent ~* "oBot") { return 403; }

Apache

# Apache serves every user agent by default.
# Make sure .htaccess has no rule like this:
# RewriteCond %{HTTP_USER_AGENT} oBot [NC]
# RewriteRule .* - [F,L]

05 · Block

How to block oBot

oBot follows robots.txt, so one rule is enough. Use a server or CDN rule only to stop spoofed copies.

robots.txt

User-agent: oBot
Disallow: /

Cloudflare

# Security › WAF › Custom rules › Create rule
Expression: (http.user_agent contains "oBot")
Action:     Block

WordPress

# WordPress serves a virtual robots.txt. Edit it with your SEO plugin:
# Yoast: SEO › Tools › File editor · Rank Math: General Settings › Edit robots.txt
User-agent: oBot
Disallow: /

nginx

# In your server { } block:
if ($http_user_agent ~* "oBot") {
    return 403;
}

Apache

# .htaccess
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} oBot [NC]
RewriteRule .* - [F,L]
</IfModule>

06 · User agents

User agents we see for oBot

The user agent published by the operator:

Mozilla/5.0 (compatible; oBot/2.3.1; +http://www.xforce-security.com/crawler/)

07 · Verification

Is it really oBot?

oBot’s operator publishes no IP ranges or hostnames, so requests cannot be verified. Treat the user agent as a claim, and watch your logs for unusual request rates.

FAQ

Questions about oBot

What is oBot?

oBot is IBM's crawler that categorizes web pages for content filtering and security databases.

How do I block oBot?

Add a robots.txt group for the crawler ID oBot with Disallow: /.

How can I verify oBot?

Compare the request IP with the IPv4 and IPv6 ranges listed on IBM's oBot crawler page.

Last reviewed Oct 8, 2026

Your site

See which pages oBot crawls on your website

Log Hero reads your server logs and shows every AI bot, every page, every day.

Sign up with Google

Free during early access