iAskBot: Robots.txt & Crawl Policy Reference
Technical reference for the iAskBot User-Agent token associated with iAsk AI Search. Learn how to verify requests when no public crawler contract is available.
AI Summary: iAskBot is a browser-like User-Agent token associated with iAsk AI, a cited-answer search engine for students and researchers. iAsk's public product page confirms the search product, but no first-party crawler policy was found that establishes IP verification, robots compliance, or a universal crawl contract. Treat the token as an observed identifier, verify it in logs, and use targeted controls only after deciding whether iAsk search visibility is valuable.
Role and policy boundary
The iAsk website describes iAsk AI as a search engine and homework helper that answers natural-language questions using cited sources. Its product pages also describe URL summarization, document analysis, browser search, and an API. This establishes the product context: iAsk needs access to web content to provide source-backed answers, but it does not by itself prove how every iAsk-related HTTP request is collected.
The registry-listed string contains iAskBot/1.0 inside a browser-compatible User-Agent. The public iAsk product page does not publish a crawler policy specifying a fixed User-Agent, source IP ranges, robots behavior, rate limits, or contact process. Accordingly, this profile labels the crawler partially documented. Do not convert the product description into a claim that iAskBot trains models, respects robots rules, or always uses this exact header.
If you want to communicate a preference to traffic that declares the token, publish a narrow robots group:
User-agent: iAskBot
Disallow: /
For a selective search-visibility policy:
User-agent: iAskBot
Allow: /docs/
Allow: /public/
Disallow: /account/
Disallow: /checkout/
Disallow: /api/
A robots rule is a published preference, not authentication. If the request is unwanted or the token is spoofed, enforce the decision at the WAF, application, or identity layer.
Layered verification
Start with request logs. Match iAskBot case-insensitively, but preserve the complete header and record the IP address, path, status, response size, redirect chain, timestamp, and rate. The browser-like prefix makes broad matching risky: a legitimate browser or unrelated automation could contain a similar suffix, and a real iAsk fetcher may use a different configured header.
Next, examine the source network. No authoritative iAsk IP range or reverse-DNS procedure was identified in the public product documentation. Treat ASN or reverse-DNS results as corroborating telemetry, not proof, and do not allowlist an address solely because the User-Agent claims iask.ai.
Evaluate /robots.txt and page directives independently. If you permit the token, test a representative public page and confirm the rule is syntactically correct. If you want to remove a page from ordinary search indexing, use:
<meta name="robots" content="noindex, nofollow">
or:
X-Robots-Tag: noindex, nofollow
These directives do not guarantee that an unknown or user-directed fetcher will stop reading the response. For sensitive pages, use authentication and authorization rather than metadata or User-Agent matching.
WAF and Nginx remediation examples
If logs show sustained traffic that declares the token and you have decided not to provide iAsk visibility, use a narrow WAF expression:
{
"description": "Block declared iAskBot traffic",
"expression": "lower(http.user_agent) contains \"iaskbot\"",
"action": "block"
}
This catches the declared string but not a request that rotates its User-Agent. For Nginx, scope the rule to the routes where extraction is unwanted rather than automatically blocking every site request:
map $http_user_agent $block_iaskbot {
default 0;
~*iAskBot 1;
}
server {
location ~ ^/(account|checkout|api|internal)/ {
if ($block_iaskbot) { return 403; }
try_files $uri $uri/ =404;
}
}
Test in staging and review false positives. Because the iAsk crawler contract is not publicly verified, combine the header rule with rate limiting, route authorization, and behavioral bot controls if the threat is scraping rather than simply search indexing.
Review checklist
Confirm the exact header in your own logs before naming the traffic iAskBot. Compare the observed product behavior with the current iAsk AI product page and record that no public first-party crawler contract was found at the time of review. Decide whether to allow public documentation, block the identifier everywhere, or apply a route-specific restriction.
Then publish and test the matching robots group, if appropriate. Verify response status, redirect behavior, HTML metadata, and X-Robots-Tag independently. If active enforcement is required, deploy the narrow WAF or Nginx rule, monitor for spoofing and User-Agent rotation, and protect private routes with authentication. Revisit the profile if iAsk publishes a formal crawler policy or changes its token.
References
- iAsk AI — official product page describing iAsk's cited-answer search, URL summarization, document analysis, and browser-search features.
- Google Robots.txt Introduction — general guidance on robots directives and their limitations.
Need to optimize your entire site for AI search visibility? Run a comprehensive audit with Geolify.ai.