Forum Moderators: open

Message Too Old, No Replies

Apple bot? Not according to DNS

         

dstiles

10:00 am on Dec 7, 2021 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



As of a few days ago I'm getting a relatively high number of hits with an Applebot user-agent. The bots come from unexpected sub-ranges of Apple's 17.x.x.x block. The DNS shows non-bot. I'm assuming these are bad bots, nothing to do with apple.

UA:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1.1 Safari/605.1.15 (Applebot/0.1; +http://www.apple.com/go/applebot)

IP ranges:
17.58.112.* (single IP)
17.58.117.* (two IPs)

DNS (typically):
usmsc2-extxfr-001.dns.apple.com. hostmaster.apple.com

I have tried to find what purpose these IP ranges serve - cloud, perhaps? - but I cannot find any way of getting a sensible Apple whois response. The nearest I can get is the almost-impossible-to-understand [whois.nic.apple...] but the response is not adequate.

brotherhood of LAN

10:27 am on Dec 7, 2021 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I've seen it from 326 IPs over the past year, here's the other ranges.

17.58.96.*
17.58.97.*
17.58.98.*
17.58.100.*
17.58.101.*
17.58.103.*
17.121.112.*
17.121.113.*
17.121.114.*
17.121.115.*

DNS resolves to *.applebot.apple.com for all but 1 of them. Try looking at the RDAP records if you haven't already rdap.arin.net/registry/ip/ [IP here]

dstiles

4:16 pm on Dec 7, 2021 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I allow the ranges for applebot...
17.58.96.0/22
17.121.112.0/20

I haven't seen the 17.58.10* ranges but I will update the 58 range to /21 to cover them. Thanks.

However, none of the ones I mentioned in the OP is in those ranges. :(

dstiles

7:36 pm on Dec 16, 2021 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



A few days ago I wrote to an Apple support email address I found on their bot site. Surprisingly I got back a "thank you, looking into it" email. I've just received a second email from them...

"We really appreciate that you highlighted the issue to us. We have found the
issue and resolved it."

Doesn't say who was at fault - applebot or a third party - but at least it should now be fixed. At any rate, I haven't seen the offending hits since a few hours after sending the initial email.

brotherhood of LAN

9:51 pm on Dec 16, 2021 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I guess if the IPs don't resolve to applebot in the near future you'll at least know the requests are/were not legitimate.