Anyone can call themselves GPTBot. Upload your logs and we match the IP of every visit against the official lists from OpenAI, Anthropic, Perplexity, Google and others, to tell genuine bots from impersonators.
The analysis runs in your browser. We neither store nor send your logs: we only download each company's public IP lists.
The access log is a text file your server fills in with every visit: who came in, from which IP and under which name. You don't need to install anything, just download it. Pick your hosting:
Bluehost, GoDaddy, Namecheap, HostGator and many others use cPanel. If you log in and see a page full of icons grouped in sections, it's cPanel.
.gz file downloads.For more days, tick "Archive logs in your home directory" on that same page. From then on, previous months show up under "Archived Raw Logs".
access_ssl_log with the green arrow. If your site doesn't use https, use access_log.Very large files can make Plesk slow or unresponsive. Also download the rotated ones (access_ssl_log.processed, .1.gz…) and upload them together.
SiteGround keeps 30 days. Older days live in your domain's logs folder, reachable from the File Manager.
On Hostinger shared plans you can view the logs but not download them.
logs folder.access.log, click the three dots and then Download.Kinsta only keeps 4 days. For more history, download it every few days or connect it to Bee LLM.
On a server running Nginx or Apache, the logs are in:
/var/log/nginx/access.log/var/log/apache2/access.log/var/log/httpd/access_logTo grab them along with the previous, already compressed days:
scp user@your-server:/var/log/nginx/access.log* .
If your site sits behind Cloudflare, set real_ip_header CF-Connecting-IP (Nginx) or mod_remoteip (Apache). Otherwise the log stores Cloudflare's IP and nothing can be verified.
If you don't know your hosting provider, check your invoice or welcome email, or ask whoever built your site. The quickest route is asking support with this message:
Using Cloudflare? The free plan doesn't provide logs with each visitor's IP. Ask the hosting provider behind it.
The User-Agent is a string the requester writes. Typing "GPTBot" there costs nothing, and plenty of scrapers do it to slip into sites that let AI bots through. If your GEO report says GPTBot visited you 10,000 times and you only looked at the name, that number may be wrong.
What is much harder to fake is the IP. OpenAI, Anthropic, Perplexity, Google, Microsoft and Apple publish the ranges they crawl from, so all you need is to check whether each visit's IP falls inside them.
openai.com/gptbot.json, searchbot.json, chatgpt-user.json).claude.com/crawling/bots.json.We fetch them from the source and refresh them every 12 hours. Bytespider, DeepSeekBot and a few others publish no list and show up as "not verifiable". But if one IP claims to be three or more different bots, we flag it as an impersonation: it is a tool or scraper trying names.
Any GEO audit should keep the two apart. A detected bot claims to be GPTBot. A verified bot claims to be GPTBot and also comes from an OpenAI IP. Only the second one counts as a real AI visit.
The same goes for your WAF or Cloudflare rules: never allow a bot by its name. If you allow "GPTBot" without checking the IP, you are also letting in everyone pretending to be it.
Google-Extended is only a robots.txt token telling Google whether it may use your content in Gemini. It makes no requests. A visit presenting itself as Google-Extended is not from Google. Applebot-Extended works the same way.
Your server may be logging Cloudflare's IP instead of the visitor's. The tool detects this and warns you. To fix it, enable real_ip_header CF-Connecting-IP in Nginx or mod_remoteip in Apache and test again with fresh logs.
Bee LLM connects your logs and checks every day whether ChatGPT, Gemini and Perplexity name your brand when people ask about what you sell. Start free, no card needed.
Try it free