What is babbar.tech?

Barkrowler is the web crawler operated by Babbar, a French SEO analytics company founded in 2019 and based in Évreux, France. It systematically follows links found on public pages to build Babbar’s graph representation of the web — the underlying dataset behind the company’s backlink mapping, page-popularity scoring, and semantic content analysis tools, sold to SEO professionals, agencies, and marketers under a subscription model.

Barkrowler identifies itself with a documented user-agent string, self-reports as version 0.9, and publishes a reverse DNS suffix (babbar.eu) that genuine requests should resolve to. Babbar also states it uses the crawler-commons toolset to parse and honor robots.txt, including crawl-delay directives, and it maintains a published JSON file of its current IP ranges specifically so site operators can validate traffic against something more reliable than a self-reported string. In DataDome’s taxonomy, Barkrowler sits with commercial SEO crawlers — automated, non-malicious by design, but valuable to verify before granting it unrestricted access, since its identity is easy to imitate and its crawl footprint can be substantial on larger sites.

Legitimate use cases

  • Backlink graph construction. Barkrowler’s primary purpose is discovering and following links across the public web to maintain Babbar’s link database, the foundation of its SEO metrics.
  • Semantic and content analysis. Crawled pages feed the content-classification and topical-relevance features Babbar sells alongside its link data.
  • Redirect and error verification. Barkrowler deliberately retries pages returning 301 redirects or 404 errors, to confirm whether an issue is temporary or reflects a genuinely broken or moved resource, rather than assuming failure on the first attempt.
  • Nofollow-aware but not nofollow-restricted crawling. Like most SEO crawlers, Barkrowler still visits pages linked with rel="nofollow", since that attribute affects ranking-signal computation rather than crawl access.
  • Free-tier discoverability. Babbar offers free account access to its tools, meaning some of the traffic hitting a given site originates from independent users running lookups rather than solely from Babbar’s own scheduled crawls.

Suspicious or abusive use cases

Barkrowler’s traffic is generally not adversarial by design, but its identity string is trivial to copy, and its behavior can be mistaken for — or deliberately disguised as — something else:

  • User-agent spoofing for scraping. Because Barkrowler’s string is public and well documented, a scraper can adopt it to blend into expected SEO-crawler traffic and avoid triggering a bot challenge.
  • Session-parameter misclassification. Babbar itself notes that URLs containing session parameters can cause Barkrowler’s own requests to be mistaken for login attempts or brute-force activity — a known false-positive pattern worth accounting for before assuming malicious intent.
  • Crawl-budget consumption on large sites. Because Barkrowler retries redirected and missing pages rather than dropping them immediately, and crawls at a fixed politeness interval regardless of site size, large sites with deep link graphs can see a meaningful, sustained share of automated traffic from this identity.
  • Competitive data harvesting via a legitimate-looking identity. Since Babbar’s own tools are marketed for competitor analysis, some site owners specifically want to prevent competitors from easily obtaining backlink and content data about them — a different motivation for blocking than a typical security concern, but a legitimate one.
  • Traffic misattributed during incident response. Because Barkrowler’s request rate is deliberately capped at one request per 2.5–5 seconds, a much higher-volume burst claiming the same identity is far more likely to be an impersonator than genuine Barkrowler traffic.

 

Spoofed Barkrowler traffic does not alter Babbar’s actual backlink graph or SEO metrics — those are built only from data Babbar’s own infrastructure collects. The impact of impersonation is local to the receiving site: extra load, noisy logs, or a false sense of security from an allowlist rule that trusts the string rather than the source.

Why is it calling your server?

Barkrowler crawls essentially any page that has been publicly linked to or cited somewhere on the web, without requiring the site owner to opt in or register anything. A few practical points worth knowing:

  • No registration needed. Unlike bots tied to a specific account relationship, Barkrowler discovers your site the same way any web crawler does — by following a link to it — so its presence doesn’t necessarily mean anyone at your organization uses Babbar’s tools.
  • Persistence on errors is intentional. Repeated requests to a redirected or missing URL are Barkrowler double-checking that the state is real rather than temporary, not a sign of malfunction.
  • Crawl volume scales with link visibility. A site that is heavily linked to, or actively being analyzed by a Babbar customer (including a competitor), will see more Barkrowler traffic than one with a sparse backlink profile.
  • Content is not retained verbatim. Babbar states it stores links and page meta-information rather than full page content, and does not store personally identifiable data from crawled pages.

Threat research insights on babbar.tech

All data in this section are produced by DataDome's Galileo Threat Research team from our proprietary detection network and reviewed by human analysts.

Verified Bot A verified bot has high identification strength
Verified
Robots.txt Compliance Whether this bot respects robots.txt directives
Respected
Identification Strength How confidently DataDome can identify this bot
High

Traffic origins

Top 15 countries by bot traffic

FR FR 100.0%

Most used autonomous system (AS)

Top 5 by traffic share

Babbar SAS
99.89%
Scaleway SAS
0.09%
OVH SAS
0.02%
Traffic Occupancy
<0.1%

On average, occupy <0.1% of the traffic from bots in the directory

Authorization Rate
0%

Businesses decide to authorize this bot 0% of the time

How to detect and authenticate babbar.tech?

  1. Check the user-agent string, but treat it as a starting point rather than proof: Mozilla/5.0 (compatible; Barkrowler/0.9; +https://babbar.tech/crawler). This string is publicly documented and easily copied.
  2. Run a reverse DNS lookup on the source IP. Babbar documents that genuine Barkrowler traffic resolves to a hostname ending in babbar.eu. A request claiming to be Barkrowler that doesn’t resolve this way should not be trusted on the user-agent alone.
  3. Perform forward-confirmed reverse DNS. Resolve the hostname returned by the reverse lookup and confirm it maps back to the same source IP before treating the request as verified.
  4. Cross-check against Babbar’s published IP range file, available at babbar.tech/barkrowler-ip-ranges.json, and keep it refreshed rather than hardcoding a static list, since crawler infrastructure ranges can change.
  5. Evaluate request cadence. Genuine Barkrowler traffic is throttled to roughly one request per 2.5 seconds to the same IP on a domain and one per 5 seconds to the same host overall. Traffic far exceeding that rate under the same identity is inconsistent with documented behavior.
  6. Watch for session-parameter and login-path requests. Babbar acknowledges its own crawler can trigger session- or login-pattern false positives; distinguishing genuine Barkrowler traffic from an impersonator matters more on these paths than on ordinary content pages.
  7. Do not rely on ASN alone. Babbar’s crawling infrastructure and hosting arrangements are not as widely documented as major cloud providers’ ASNs, so reverse DNS and the published IP list are the stronger signals here.

Should you block it?

Whether to allow Barkrowler depends less on security risk and more on whether the site benefits from being represented in Babbar’s SEO tools — including tools competitors may use to analyze your backlink profile and content strategy. Reasonable grounds to restrict or block it include:

  • the traffic fails reverse DNS or IP-range verification and is therefore not genuine Barkrowler;
  • the site owner has no interest in appearing in Babbar’s SEO metrics or does not want competitor-facing tools indexing its backlink profile;
  • Barkrowler’s crawl volume is measurably affecting server performance on a large or resource-intensive site;
  • the traffic is repeatedly hitting session-gated or login paths in a way that resembles credential probing rather than link discovery; or
  • the site wants to limit all third-party SEO crawlers as a matter of policy, regardless of vendor.

If the goal is simply to reduce load rather than eliminate the bot entirely, a crawl-delay directive is a lighter-touch option than an outright block, since Babbar states it honors this directive.

How to manage babbar.tech?

  • Use robots.txt for baseline control. Barkrowler is documented to respect robots.txt, including partial disallows:
User-agent: Barkrowler
Disallow: /wp-admin/

 

To block it entirely:

User-agent: Barkrowler
Disallow: /

 

 

  • Set a crawl delay instead of blocking, if load is the only concern:
User-agent: Barkrowler
Crawl-Delay: 10

 

 

  • Verify before trusting an allowlist entry. Combine the user-agent string with forward-confirmed reverse DNS against the babbar.eu suffix and the current published IP range file — a placeholder-based rule pulling live from that JSON source is safer than a hardcoded range:
location / {
    # Validate against babbar.tech/barkrowler-ip-ranges.json
    # and confirm reverse DNS resolves to *.babbar.eu before allowing.
    if ($http_user_agent ~* "Barkrowler") {
        # apply verification logic here rather than trusting the header alone
    }
}

 

  • Exclude session-bearing and authentication paths from crawl access generally, which reduces both false-positive blacklisting of genuine Barkrowler traffic and the surface available to an impersonator using the same identity.
  • Monitor request rate against the documented politeness policy (2.5s/IP, 5s/host) rather than allowing all traffic under this identity by default, flagging bursts that exceed it for manual review.
  • Reassess periodically if the reason for blocking was competitive rather than security-driven — Babbar’s customer base and the value of appearing in its index may change your calculus over time.

DataDome recommendation

Babbar.tech’s Barkrowler should be treated as a verified, opt-in SEO crawler rather than unconditionally trusted automated traffic. Because its user-agent string is public and its abuse pattern is impersonation rather than native malice, the safest authorization model combines forward-confirmed reverse DNS against the babbar.eu suffix, cross-referencing against Babbar’s published IP range file, and behavioral validation against its documented politeness policy — not a user-agent match on its own. Sites with no interest in SEO-tool visibility, or that want to limit competitor tooling access to their backlink profile, can reasonably disallow it outright without any negative operational consequence, unlike traffic tied to monitoring, failover, or notification delivery.

DataDome

See which bots and AI agents bypass your defenses

Create your account to start analyzing and mitigating malicious bots and AI-drive threats in real-time