How robots.txt Matching Works
A robots.txt file is a list of groups. Each group opens with one or more User-agent lines and continues with the Allow and Disallow rules that apply to those crawlers. A crawler reading the file does not combine every group it finds. It picks one set of rules and ignores the rest.
The tester follows the same selection order RFC 9309 describes:
- The crawler's own token. If any group names the product token, for example
GPTBot, that group applies. The comparison is case-insensitive, sogptbotandGPTBotare the same agent. - A parent token. If a hyphenated token has no group of its own, the tester falls back to the longest parent that does.
Googlebot-Imageuses theGooglebotgroup when there is noGooglebot-Imagegroup, which mirrors how Google treats its sub-crawlers. - The
*group. Only when neither of the above exists does the wildcard group apply. - Nothing. With no matching group and no
*group, every URL is allowed.
The summary card names which of these happened, so you can see at a glance whether your crawler hit its own rules or fell through to *.
The point that trips people up most is that a specific group replaces the * group instead of adding to it. Say your file has Disallow: /private/ under User-agent: *, followed by a separate User-agent: GPTBot group containing only Allow: /. GPTBot may crawl /private/, because the rules under * simply do not exist for it. If a rule should apply to a named crawler, repeat it inside that crawler's group.
Two smaller details also come from the spec. Several groups naming the same agent are merged into one, so Googlebot rules split across the file behave as if they were written together. And consecutive User-agent lines before any rule share one group, which is how you give GPTBot and ClaudeBot identical rules without writing them twice.
The crawler field accepts a bare product token or a full User-Agent string. With a full string the tester tries to extract the token first. If the Group applied row shows the * group when you expected a named one, enter the bare token instead; that always works.