You: Bot 100.0% Low
← Dashboard / Signature Detail
FR

AhrefsBot ahrefs.com

· AhrefsBot 7.0 Bot
GoodBot
Policy: rate-limit-search
Probability
100 %
Confidence
94 %
Risk Profile
VeryHigh
Threat
None
Hit Count
2
Last Seen
8s ago

Analysis

AhrefsBot ahrefs.com on /_content/Mostlyl... - caught by Cryptographically signed AI bot (Web Bot Auth RFC 9421) f..., Known bot pattern: AhrefsBot, Datacenter IP detected: AWS

Detection Signals

  • Heuristic model (late): 99 % bot likelihood (293 features) 2.44
  • Cryptographically signed AI bot (Web Bot Auth RFC 9421) from "https://ahrefs.com" 1.90
  • Known bot pattern: AhrefsBot 1.35
  • Heuristic model (early): 80 % bot likelihood (19 features) 1.21
  • Datacenter IP detected: AWS 0.72
  • Headers appear normal 0.15
Network Locale Headers Tool Transport Session Quality
Drift vs
48.3%

Fingerprint Profile

TLS Version
TLSv1.3
HTTP Protocol
HTTP/2
Protocol Client
TLS_AES_256_GCM_SHA384
TCP OS Hint
Unavailable
Fingerprint Integrity
Suspect
UA Consistency
Flagged
Headless Indicator
Low
Datacenter IP
Clean

Browser modes same browser, different modes. One row per persisted mode

Mode Observations Maturity Shift from baseline Last seen
bot-raw 2953 2953 0.00 (header order hash, upgrade insecure requests, ua family) 19:04:22
sub-resource 3 3 0.41 (header order hash, ua family, header case pattern) 15:48:57
signalr-negotiate 1 1 0.49 (ua family, header order hash, referer host family) 15:48:44
navigation 7 7 0.49 (upgrade insecure requests, ua family, header order hash) 00:14:28
4 modes across 2964 observations. See composite browser-mode fingerprints.
Endpoints Visited (2) Click to expand · stats unavailable
# Path
1 /_content/Mostlylucid.BotDetection.UI/css/sb-components.css
2 /_content/Mostlylucid.BotDetection.UI/vendor/js/htmx.min.js
Raw Requests (2) Click to expand
Time Method Path Status Prob Conf Risk Profile Action Time
18:03:35 GET /_content/Mostlylucid.BotDetection.UI/css/sb-components.css 200 100 % 50 % VeryHigh rate-limit-search 202.5ms
09:29:10 GET /_content/Mostlylucid.BotDetection.UI/vendor/js/htmx.min.js 200 100 % 50 % VeryHigh rate-limit-search 57.4ms

Bot Probability & Confidence History

StyloBot Detection Overhead (ms)

User Agent

Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/)

Detector Contributions (19 detectors)

Detector Confidence Delta Timing (ms)
HeuristicLate
Heuristic model (late): 99 % bot likelihood (293 features)
+0.977 0.3
AiScraper
Cryptographically signed AI bot (Web Bot Auth RFC 9421) from "https://ahrefs.com"
+0.950 0.0
UserAgent
Known bot pattern: AhrefsBot
+0.900 0.3
Heuristic
Heuristic model (early): 80 % bot likelihood (19 features)
+0.603 0.1
Ip
Datacenter IP detected: AWS
+0.600 0.0
Header
Headers appear normal
-0.150 0.0
Behavioral
Request patterns appear normal
-0.150 0.1
TlsFingerprint
TLS connection appears normal
-0.150 0.0
TcpIpFingerprint
Missing connection reuse header (unusual for real browsers)
+0.200 0.0
VerifiedBot
rDNS mismatch: UA claims ahrefs.com but rDNS is proxy-fr000-san88.ahrefs.net
+0.250 191.8
Http2Fingerprint
No HTTP/2 stream priority (browsers typically use this)
+0.050 0.0
AI
AI analysis: borderline case, monitoring
+0.000 9.7
SecurityTool
No security tools detected in User-Agent
+0.000 0.0
PiiQueryString
Query string contains PII parameters: token
+0.000 0.0
RequestHydrator
Request signals hydrated to sink
+0.000 0.0
Http3Fingerprint
Connection uses HTTP/2 (not HTTP/3)
+0.000 0.0
HeaderCorrelation
Single signature per header profile
+0.000 0.0
TransportProtocol
Transport protocol analysis complete
+0.000 0.0
FastPathReputation
No known patterns in reputation cache
+0.000 0.0

Signal Intelligence

h2

protocol h2

request

protocol HTTP/2
accept_encoding deflate, gzip, br, zstd

risk

justification Classified GoodBot (probability 1.00, confidence 0.50)
friendly_pin_trace skipped:no_corroboration (UA claims AhrefsBot ahrefs.com as GoodBot)

tls

cipher TLS_AES_256_GCM_SHA384
Version TLSv1.3
version TLSv1.3

Policy applied

Hit history

No sessions recorded yet.

Sessions are created when a visitor's activity gap exceeds 30 minutes.

Effective policy
Loading effective policy…
ASP.NET Pack — Auth health
JWKS health
OK

reachable

Auth pipeline
JWKS reachable
License
Licensed

ASP.NET pack enabled

OTel Mesh — Traces

Fingerprint timeline

fbb975cff7f548979ac34955b2034d9a 0 observations

Span + log activity for this fingerprint, ordered by timestamp.

No timeline observations

OTel Mesh receiver online, but no observations seen for this fingerprint id (check W3C baggage propagation)

Operator actions

Operator actions

Block/Allow writes a scoped policy rule for this fingerprint — a policy action, applied via the live policy pipe. It is never a skip-detection bypass.

Signature: NIx1c2GxI33-arcw-r6tQQ | Processing: 203ms | Country: FR | UA: Mozilla/5.0 (compatible; AhrefsBot/7.0; +http://ahrefs.com/robot/) | First seen: 2026-07-23 09:29:10 UTC