Crawler identity
Who we are when we touch your DNS.
We identify ourselves honestly and take only what is public. If you see us in your logs, this is what we were doing.
User-agent
FirstSeenBot/1.0 (+https://firstseen.io/bot) What we request
- DNS — MX, TXT (SPF/DMARC/DKIM/BIMI/MTA-STS), NS, CAA, DS. Standard resolution against public authoritative servers.
- HTTPS — only well-known policy paths:
/.well-known/mta-sts.txtand equivalents. We do not crawl site content. - CT + zones — read from public logs and authorised registry feeds. No request hits your servers for these.
What we never do
- We do not crawl page content, forms, or anything behind authentication.
- We do not attempt logins, submit forms, or probe for vulnerabilities.
- We do not collect email addresses or any personal data — see /data.
- We honour a reasonable request to stop — email optout@firstseen.io.
Rate & politeness
Requests to any single domain are infrequent and spread out — we snapshot nightly, not continuously. If our traffic is ever a problem, tell us and we will back off immediately.