Over thirteen days in August 2026, 1,129 automated visitors showed up on our site as AI assistants fetching a page for a human. We asked for their papers. Verifying AI traffic means checking that claim against the address ranges published by the operators and against reverse DNS (Domain Name System) resolution. At Fast Growth Advisors, no AI visibility figure is produced any other way.
876 were lying.
That number changes how you should read everything you think you know about your AI traffic. Including, perhaps, statistics published by major players in the market.
Why doesn’t the user-agent prove a bot’s identity?
Because it is a line of text the visitor writes itself, and nothing, technically, stops it from putting “Googlebot” or “ChatGPT-User” there. The user-agent is the announcement an automated visitor makes of its identity on arrival at a server.
Nearly every measurement tool counts that line and stops there. Scrape ratios, error rates, traffic shares: the headline figures published on AI crawling are computed on it.
Yet there is a way to verify.
Google, OpenAI, Microsoft and others publish the IP (Internet Protocol) address ranges their bots operate from, or a reverse-resolution mechanism that confirms identity both ways. It is public, documented and free. Google’s documentation, for instance, describes a reverse DNS lookup followed by a forward lookup whose results must match.
At Fast Growth Advisors, we applied it to every request in our server logs, across two sites, from 11 to 23 August 2026. Each automated visitor received a verdict: authenticated, proven spoof, unverifiable, or undecided.
First result, simple to tell: 67 distinct addresses claimed to be Googlebot on our main site. Seven belonged to Google.
The other sixty?
Machines rented from consumer hosting providers, duckdns.org and digivps.com among others. Anyone can rent a server and write “Googlebot” in their header. Many do, because the disguise opens doors that firewalls close to anonymous visitors.
On our second site, 20 addresses claimed to be Googlebot, and the seven authentic ones were the same. That gap between the two sites measures each site’s exposure to impostors: a control figure that actually controls something.
What error rate does AI traffic show once identity is verified?
Almost none: authenticated requests find their page 99.4% of the time, and the error rate attributed to AI belongs mostly to the impostors.
This result concerns the category that matters: requests presenting as an AI fetching a page on a human’s behalf, the traffic everyone wants the curve of. Of 1,129 declared requests, 154 were authenticated and 876 were proven spoofs, the rest being unverifiable or undecided.
| Verdict | Requests | Pages found | Missing pages |
|---|---|---|---|
| Authenticated | 154 | 99.4% | 0.0% |
| Not verified | 99 | 87.9% | 1.0% |
| Proven impersonation | 876 | 30.7% | 69.1% |
| All verdicts combined | 1,129 | n.a. | 53.7% |
No authenticated request knocks on the wrong door.
Spoofs, on the other hand, grope around: 69.1% of their requests aim at pages that do not exist. They probe and hunt for weaknesses more than for content.
All verdicts combined, the only reading a non-verifying tool can produce, you get a 53.7% error rate.
Vercel, in the reference study on AI crawlers, publishes 34.82% of missing pages for ChatGPT and 34.16% for Claude, against 8.22% for Googlebot. Same order as our unfiltered total, never the same world as our authenticated requests.
Hence a hypothesis, which we give as such: the crawl waste attributed to AI may measure, for a large part, actors passing themselves off as AI.
We claim nothing about anyone else’s method. On our servers, the gap between the two readings is 53.7 points.
You will find the full method, the four verdicts, the breakdown by bot class across two sites and the limits of our instrument in the Fast Growth Advisors white paper Counting bots, not lies, freely available, with its PDF version.
What should be said about unverifiable bots like ClaudeBot?
That they are not impostors: not everything unverified is fraudulent, and the distinction deserves care.
ClaudeBot, Anthropic’s crawler, cannot be authenticated, because its publisher provides neither an address range nor a reverse record. An unverifiable bot, then, and not a spoof: our counts place it in a separate column. Same status for DuckDuckGo. The real question, which we leave open, is why some publishers provide the means to verify them and others do not.
Our measurements have their limits. At Fast Growth Advisors, we would rather write them down before someone finds them for us.
On our main site, 12% of AI-agent traffic came in reality from a single bot. For that one, verification did not succeed even though it should have. We have not yet worked out why, and those requests are counted separately.
Neither authenticated, nor accused.
And our volumes are what they are: 154 authenticated requests over thirteen days, two small-business sites. We do not claim to describe the web; we describe a method, and what it changes to the figures when you apply it. Anyone who runs the same measurement on their own logs will find different proportions, but the same gap between what bots declare and what verification confirms.
Why can the referral channel be 88.9% false?
Because the “referral” category, supposed to count traffic coming from other sites, also swallows internal navigation.
Over the same window, it weighed 12,087 requests in the logs analysed by Fast Growth Advisors. Of those, 10,740, or 88.9%, came from a visitor already on the site clicking through to another of its pages. Identity verification is therefore not the only place where a dashboard lies by construction. For a marketing team, the channel it reports on each month was mostly counting its own site.
The fourth acquisition channel on the measurement screen was not an acquisition channel.
How many authentic AI referrals in the batch? Four.
With the usual caveat, which applies to every tool on the market: the native ChatGPT and Claude apps send no referrer header, so that traffic is structurally undercounted. A “zero AI referrals” shown by a tool describes a blind spot, and nothing more.
Which question should you ask your AI traffic measurement tool?
Just one: what does bot identification rest on?
No need to reproduce the Fast Growth Advisors setup to act. Asked of your measurement tool, or of the vendor selling you an AI visibility report, that question is enough to place what its figures are worth. In our logs for August 2026, 876 of the 1,129 requests declared as AI were proven spoofs.
If the answer is “the user-agent,” you now know what you are reading: a volume that may be mostly false, an error rate that is not yours, and content budget decisions made for visitors who do not exist.
A counter that does not verify identity does not count bots. It counts lines of text anyone can write.
Counting bot visits means verifying their identity, since the declared agent can be forged. Perplexity publishes the address ranges of its two bots, which makes them checkable. Perplexity visibility, the engine that cites the most.
Sources
- Vercel and MERJ (web analytics firm). The rise of the AI crawler, 17 December 2024. Server-log study: 34.82% of fetches to missing pages (404) for ChatGPT and 34.16% for Claude, against 8.22% for Googlebot. vercel.com
- Google Search Central. Verifying Googlebot and other Google crawlers, updated 20 March 2026: verification by reverse then forward DNS lookup, or by matching against the IP ranges published in JSON format. developers.google.com
- OpenAI. Overview of OpenAI Crawlers: user-agents and published address ranges for GPTBot, OAI-SearchBot and ChatGPT-User (gptbot.json, searchbot.json, chatgpt-user.json). developers.openai.com
- Fast Growth Advisors. In-house measurement on server logs, two sites, 11 to 23 August 2026: 1,129 requests declared as AI agents (154 authenticated, 876 proven spoofs); 67 and 20 “Googlebot” addresses with 7 authentic on each; referral category of 12,087 requests including 10,740 internal navigation and 4 authentic AI referrals. Full method and tables in the white paper Counting bots, not lies.
FAQ
How does an AI bot prove its identity, and why isn’t the user-agent enough?
Through its IP addresses or reverse DNS, never through its user-agent.
The user-agent is a line of text the visitor writes itself, and nothing stops it from saying “Googlebot.” Proof goes through the address ranges published by the operators, or through a reverse resolution confirmed both ways. In the Fast Growth Advisors logs, 67 addresses claimed to be Googlebot and only seven belonged to Google.
Why might my AI crawl error rate be false?
Because a non-verifying tool adds real bots and impostors together.
On fast-growth.fr in August 2026, authenticated AI requests found their page 99.4% of the time, while spoofs hit a missing page 69.1% of the time. All verdicts combined, the reading reached a 53.7% error rate, a figure driven by the impostors. The error rate attributed to AI may therefore measure, in part, actors passing themselves off as AI.
Is ClaudeBot an impostor since it cannot be authenticated?
No: unverifiable does not mean spoofed.
ClaudeBot cannot be authenticated because Anthropic publishes neither an address range nor a reverse record. An unverifiable bot is not, for all that, a proven spoof, and Fast Growth Advisors counts place it in a separate column, like DuckDuckGo. One question stays open: why do some publishers provide the means to verify them, and others not?
How do I know what an AI-visibility report is worth?
Ask what bot identification rests on.
If the tool or vendor answers “the user-agent,” the announced volume of AI traffic may be mostly false and the error rate is not yours. Check too how the referral category is counted, since internal navigation often inflates it. And keep in mind that the native ChatGPT and Claude apps send no referrer header: real AI visits are undercounted.