Spoofed Bot Defense & FCrDNS
Unmask forged User-Agents using RFC-compliant Forward-Confirmed Reverse DNS (FCrDNS) lookups and BGP Autonomous System Number (ASN) verification.
The Forged User-Agent Attack Vector
Because HTTP request headers are client-controlled, malicious scrapers, vulnerability scanners, and content aggregators arbitrarily inject legitimate crawler signatures into the User-Agent header:
Relying solely on User-Agent string parsing creates severe vulnerability to unauthorized scraping, credential brute-forcing, and skewed analytics.
FCrDNS Verification Algorithm (RFC 8482)
Tracium verifies crawler authenticity using Forward-Confirmed Reverse DNS (FCrDNS):
1. Ingress Request:
Client IP: 66.249.66.1 | Claims: "Googlebot/2.1"
│
▼
2. PTR DNS Lookup:
Query: 1.66.249.66.in-addr.arpa
Result: crawl-66-249-66-1.googlebot.com
│
▼
3. Suffix Validation:
Assert: Hostname ends with official domain (".googlebot.com" or ".google.com")
│
▼
4. Forward Confirmation:
Query: A/AAAA record for "crawl-66-249-66-1.googlebot.com"
Result: 66.249.66.1
│
▼
5. Identity Verification:
66.249.66.1 === 66.249.66.1 ──► Verified Authentic Crawler (is_spoofed: false)If any phase fails—such as NXDOMAIN, hostname suffix mismatch, or mismatched forward A records—the connection is immediately tagged as is_spoofed: true.
BGP ASN & Hosting Provider Heuristics
In addition to FCrDNS, Tracium correlates client IP addresses with authoritative BGP Autonomous System Numbers (ASN):
Googlebot IP terminates on AS15169 (Google LLC). Verified authentic.
Googlebot signature terminating on AS14061 (DigitalOcean) or AS24940 (Hetzner). Flagged as spoofed proxy.
Automated Edge Tagging & Firewall Rules
Downstream servers receive the calculated classification via the X-Tracium-Spoofed request header, allowing origins to issue 403 Forbidden or invoke rate limiting immediately.