How to block EFF DNT policy checker
Operated by Electronic Frontier. is operated by the Electronic Frontier Foundation to verify whether websites properly implement Do Not Track policies. The bot checks sites for com… Developer Helper Assists with testing, debugging, and ensuring website functionality
How it identifies itself
Mozilla/5.0 (compatible; EFF DNT policy checker +https://www.eff.org/dnt-policy) for questions or concerns email dnt-policy at eff.org
nginx
In the server block, then reload.
# In the server block. 403 rather than 444: a closed connection tells the
# operator nothing, and an agent that gets a status code can log it.
if ($http_user_agent ~* "(EFF DNT policy checker)") {
return 403;
}
Apache
In .htaccess or the vhost.
BrowserMatchNoCase "EFF DNT policy checker" bad_bot
<RequireAll>
Require all granted
Require not env bad_bot
</RequireAll>
Cloudflare
Security → WAF → Custom rules.
# Security → WAF → Custom rules, action: Block (http.user_agent contains "EFF DNT policy checker")
WordPress
A child theme's functions.php, or a small plugin.
// functions.php of a child theme, or a small plugin. Runs before WordPress
// builds the page, so a blocked agent costs one PHP process and no queries.
add_action('init', function () {
$agent = $_SERVER['HTTP_USER_AGENT'] ?? '';
foreach (['EFF DNT policy checker'] as $needle) {
if (stripos($agent, $needle) !== false) {
status_header(403);
exit('Blocked: EFF DNT policy checker');
}
}
});
A rule on the user agent is a rule on a string it chose
The server rules match on a header the requester sets, which stops the agent that says who it is and not the one that copies somebody else's name. Botscope verifies identity against DNS and published address ranges, records which check decided each request, and shows you the ones that lied.