SEO Guide

robots.txt Directives Explained: User-agent, Allow, Disallow, Crawl-delay and Sitemap

By ToolFlic Expert Team Updated 1054 words

A robots.txt file is a plain-text file at https://yourdomain.com/robots.txt that tells well-behaved crawlers which paths they should not request. It uses a handful of directives grouped by user-agent. The single most important thing to understand is that robots.txt is a request to polite bots, not a lock - it controls crawling, not indexing, and it is the wrong tool for hiding anything private.

This page explains each directive, how path matching really works, and the traps that block CSS, open up admin folders, or leak URLs anyway. Build a correct file with the free robots.txt generator and cross-check your crawl budget against the broken link checker.

Where robots.txt lives and what it controls

The file must sit at the root of your domain, exactly one per host and protocol: https://example.com/robots.txt. Subdomains get their own. Crawlers fetch it before crawling anything on that host.

robots.txt governs crawling (whether a bot may fetch a URL). It does not control indexing: a page blocked in robots.txt can still appear in search results if other pages link to it, and because the bot cannot fetch the page it cannot see a noindex tag on it. To actually keep a page out of the index, let it be crawled and add a noindex meta tag or an X-Robots-Tag header - do not use robots.txt for that.

The directive anatomy: user-agent, allow, disallow

A robots.txt file is a set of groups. Each group starts with a User-agent: line naming which bots the rules apply to, followed by the rules for that bot. A blank line separates groups.

DirectiveMeaningExample
User-agentWhich bot the next rules apply to; * = all botsUser-agent: *
DisallowPath the bot must not requestDisallow: /wp-admin/
AllowException re-permitting a path (paired with a broad Disallow)Allow: /wp-admin/admin-ajax.php
SitemapAbsolute URL of an XML sitemap (may be on another host)Sitemap: https://example.com/sitemap.xml
Crawl-delaySeconds between requests; honoured by some bots, not GoogleCrawl-delay: 1

The classic pair on a WordPress site is Disallow: /wp-admin/ with Allow: /wp-admin/admin-ajax.php - block the admin area but let the one endpoint that many themes rely on through.

Matching rules: prefixes, the $ anchor and * wildcards

Paths are matched as prefixes, not exact strings: Disallow: /private also blocks /private.html and /private/report.pdf, because they all start with "/private". Put the trailing slash deliberately - Disallow: /articles catches /articles, /articles-old and /articles/123, while Disallow: /articles/ only catches the folder and its contents.

Two special characters refine matching: * matches any run of characters (so Disallow: /*.pdf$-style patterns or /tmp* work), and $ anchors the end of the URL, so Disallow: /*.gif$ blocks URLs that end in .gif but not .gif?v=2. When both an Allow and a Disallow match a URL, the longest (most specific) path wins, regardless of order - that is how the admin-ajax exception survives the broad /wp-admin/ block.

Crawl-delay, sitemap lines and comments

Crawl-delay asks a bot to wait N seconds between hits. Google explicitly ignores it (it self-throttles), but Bing and several AI/general crawlers may honour it, so it is a reasonable hammering guard for those agents. Comments start with # and run to end of line.

The Sitemap: line is independent of the user-agent groups - it can appear anywhere and, unlike every other directive, it may point at a different host. List all your maps there so bots that read robots.txt still find them.

The mistakes that silently hurt you

Most robots.txt damage is accidental. The recurring ones:

Blocking your assets. A broad Disallow: / on * during development is easy to forget and ships live, hiding the whole site. Even more subtle: blocking /wp-content/, the CSS folder or the images folder stops Google rendering pages and can hurt ranking, because the crawler cannot load the page the way a user sees it.

Using it for privacy. robots.txt is public and Disallow: lines are a published list of what you wanted to hide; anything secret belongs behind authentication or a noindex, never only in robots.txt.

Spaces and case. Directive names are case-sensitive (Disallow, not disallow), and stray spaces around the colon break parsing on some crawlers. Also remember an empty Disallow: means allow everything, not block everything - the opposite of what many people expect.

Test before you trust it

Write the rules, then verify behaviour rather than assuming. Fetch https://yourdomain.com/robots.txt in a plain browser to confirm it exists and is served as text (not a 404 or an HTML error page). In Search Console the Robots testing report and URL Inspection show whether a specific URL is blocked by your file, and the broken link checker confirms you have not blocked paths that your own pages still link to.

Frequently Asked Questions

Can robots.txt keep a page out of Google?

Not reliably, and often counter-productively. Blocking a URL in robots.txt stops Google fetching it, which also stops it seeing a noindex tag - so the page can still get indexed from links pointing to it, without you ever learning it is there. To keep something out of the index, let it be crawled and return a noindex directive, or protect it with a password.

What does Disallow: / mean?

It blocks the whole site for that user-agent group. Combined with User-agent: * it tells every polite crawler to fetch nothing. That is fine for a staging site but catastrophic if it ships to production, and it is the most common robots.txt accident.

Does Google respect Crawl-delay?

No, Google ignores Crawl-delay and decides its own pace. Bing and a number of other and AI crawlers may honour it, so it can still be useful to protect a slow server from those bots.

Allow versus Disallow - which wins?

The most specific (longest) matching path wins, not the one that appears first. That is why Disallow: /wp-admin/ with Allow: /wp-admin/admin-ajax.php lets the one ajax endpoint through.

Where should the file live?

One file at the root of each host and protocol, at /robots.txt, served as text. Subdomains need their own. A missing robots.txt is perfectly fine - crawlers simply assume everything is allowed - so you do not need a file unless you want to restrict something.

Do I need robots.txt at all?

Only if you want to block something or advertise a Sitemap. An empty or absent robots.txt means allow-all, which is the right default for most sites. Add rules deliberately, not defensively.

More Guides

How to Compress an Image to 100 KB (or Any Exact Size) Without Losing Quality

A tested method for hitting 100 KB, 50 KB, 20 KB or 500 KB exactly: dimension math, quality steps, and the formats that shrink best. Works on phone and desktop, no upload required.

Passport and Visa Photo Sizes by Country (US, UK, Schengen, India, Canada, Australia, China)

Exact photo sizes for US, UK, Schengen, India, Canada, Australia and China applications β€” millimetres, pixels, KB limits, background and head-height rules, plus how to prepare a compliant file.

How to Reduce PDF Size for Online Applications (2 MB, 5 MB, 100 KB and Other Limits)

Get scanned documents, CVs and certificates under any portal limit with real downsampling settings β€” plus why your PDF is huge, why merging adds pages, and how to keep text selectable.

JSON Formatter for API Debugging: Nine Common Errors and Their Fixes

Line and column errors explained: trailing commas, single quotes, unquoted keys, escaping, arrays versus objects, and the XML-to-JSON gotchas that break integrations. Paste and validate instantly.

How to Merge PDFs on a Phone for Free (Android and iPhone), No Upload

Scan pages, join them into one PDF and email it - all in the browser on your phone. Real page-count and size limits, the scan-then-merge workflow, and how to stay under a 2 MB portal cap without a desktop or an app.

QR Code Print Rules: Size, Error Correction and Contrast That Actually Scan

The numbers that decide whether a printed QR scans: module size, quiet zone, error-correction level (L/M/Q/H), matte vs gloss, print DPI and a real test routine. Generate a print-ready code free, in the browser.

Random Passwords vs Passphrases: Entropy Maths and Real Crack Times

How many bits a password really has, why length beats symbols, honest offline-crack-time maths, and where a password manager and 2FA matter. Generate a strong random password in your browser with nothing sent anywhere.

Word Count for Assignments: Limits, What Counts, and How to Trim Safely

Exactly what a word counter counts, whether the bibliography and headings are included, why 250 words is 250 words, and how to trim to the limit without breaking citations. Count free, in your browser, with no upload.

EMI vs Mortgage Loans: Tenure, Total Interest and the 28/36 Affordability Rule

The real EMI formula, why a longer tenure lowers the payment but raises total interest, the 28/36 affordability rule, part-payment and balance-transfer maths - all worked through. Calculate free, in your browser.

Base64 Data URIs for Images: the +33% Overhead and When Inlining Wins

Why base64 costs about 33% more bytes, how data URIs save or add requests, the HTTP/2 reality, cacheability trade-offs, and inline SVG vs bitmap. Encode and decode a data URI free, in your browser.

Metric and Imperial Conversions: the Factors, the Traps and the Rounding Rules

The exact factors for length, weight and temperature, the tonne vs ton vs metric-cwt trap, rounding rules for construction and cooking, and how to convert without introducing error. Convert free, in your browser.

Website Slow? Fixing LCP, Render-Blocking JS and Core Web Vitals

What LCP, INP and CLS actually measure, lab vs field data, the biggest real fixes - image sizing, render-blocking JS/CSS, caching - and how to check server latency. Be honest that a quick checker is not PageSpeed Insights.

How to Create and Submit an XML Sitemap (and What Actually Gets Pages Indexed)

A practical, honest walkthrough: build an XML sitemap, host it, reference it in robots.txt, and submit it in Google Search Console and Bing - plus why a sitemap is a hint, not a guarantee of indexing.

Meta Description Length: The Character Band and the Pixel Cut Behind the Snippet

There is no official character limit. Here is how Google actually truncates by pixel width, the ranges that usually survive on desktop and mobile, and how to write a description that gets shown instead of rewritten.

AI Crawlers, GPTBot and llms.txt: What They Mean for Your Site

Who the AI bots are (GPTBot, ClaudeBot, PerplexityBot, Google-Extended and more), how to allow or block each in robots.txt, and an honest take on what llms.txt does and does not do.

Domain Authority: What DA Actually Measures (and Why It Is Not a Google Score)

Domain Authority is a Moz prediction, not a Google metric. What DA and PA really mean, why they differ between tools, how to use them honestly, and how our checker fetches them.

How to Find Broken Links Before They Cost You Traffic and Trust

Why 404s and dead outbound links leak value, the HTTP codes behind them, a practical one-page check workflow, and how to fix each failure - using a browser-based link checker.

Google Index vs Crawl: Two Different Things Most People Conflate

Crawling, indexing and ranking are three separate stages. What crawled-but-not-indexed really means, which signals let a page be indexed, and how to verify status honestly in Search Console.

Keyword Density: Why There Is No "Safe" Percentage to Hit

What keyword density actually measures, why chasing a target percentage is a myth, when the number is a useful red flag, and how to use a density checker without stuffing.

UTM Parameters: A Clean Naming Convention and Reusable Template

What utm_source, medium, campaign, term and content actually capture, the rules for a consistent lowercase naming scheme, a copy-paste template, and the traps that wreck attribution.

HTTP Status Codes Every Site Owner Should Recognise

A plain-language map of 200, 301, 302, 404, 410, 403 and 5xx codes, what each does to your SEO, and how to read a URL's real status without guessing.

A GDPR-Ready Privacy Policy Checklist (and Why a Generator Is Only the Draft)

What a GDPR privacy policy must disclose, the many obligations that live outside the document, how CCPA differs, and how to use a policy generator without mistaking a draft for compliance.

Plagiarism vs Paraphrasing: An Honest Guide to Originality Checks

Why a browser plagiarism checker cannot compare your text to the internet, what matched-source detection actually needs, how to paraphrase legitimately, and how to use originality tools without fooling yourself.

Reading and Writing Regular Expressions Without Fear

A plain-language tour of regex syntax, the JavaScript flags (g, i, m, s, u), capture groups, the greedy-vs-lazy and engine gotchas, and how to test a pattern safely before you ship it.

CSV to JSON: How to Convert Cleanly (Delimiters, Headers and Quoting)

The traps that silently corrupt CSV data - quoted fields, embedded commas and newlines, header-vs-array shape, auto-typed numbers and BOM - and how to convert to JSON safely.

XML to JSON: What Gets Lost and How to Convert Faithfully

XML and JSON are not equivalent trees. How attributes, repeated elements, mixed content, CDATA and namespaces map across - and where silent data loss and array-vs-object ambiguity bite.

Minify, Compress or Cache? Three Speed Levers People Confuse as One

HTML minification shrinks bytes, compression shrinks transfer, and a CDN or cache cuts latency and rework. What each layer actually changes and the order to apply them.

Formatting SQL for Readable Code Review (Without Pretending It Validates It)

A SQL beautifier only reflows text - it cannot prove a query is correct. How to format for review, pick a house style, and combine it with real validation and EXPLAIN.

MD5 vs SHA-256 (and Why Neither Should Hash Your Passwords)

What cryptographic hashes are, why MD5 is broken and SHA-256 is not, why both are wrong for passwords, and why base64 is not hashing at all.

URL Encoding and Reserved Characters: What to Escape and When

Percent-encoding, the RFC 3986 reserved vs unreserved split, the difference between encoding one parameter value and a whole URL, and the double-encoding traps that break requests.

Favicon Sizes: The Complete, Honest List (and What Actually Matters)

A favicon is not one file. Which sizes serve which surfaces - tab, apple-touch, PWA 192/512, legacy ICO - what SVG can and cannot replace, and what a generator can really output.

Unix Time and the 2038 Problem: What a Timestamp Really Is

Epoch time is seconds since 1970 UTC ignoring leap seconds. Why 32-bit signed counters roll over in 2038, the seconds-versus-milliseconds bug, and always storing UTC.

UUID vs Auto-Increment IDs: Which Primary Key to Use

Random UUID v4 versus sequential integer IDs: index locality, key size, global uniqueness, enumeration risk, and the time-ordered middle ground (UUIDv7/Snowflake/ULID).

How to Upscale an Image Without Pixelation (Honest Limits)

What 2x/4x/8x interpolation really does, why enlarging cannot invent captured detail, smooth versus nearest-neighbour, and when upscaling helps versus when to leave the image alone.

WebP vs JPEG: When to Use Each (and When Neither)

WebP is 25-35% smaller and adds transparency and animation, but JPEG still wins on reach. When each fits, lossy versus lossless, and how compatibility and the quality slider change the choice.

PDF to Word: What 'Editable' Really Means (Digital vs Scanned)

Digital PDFs carry a real text layer and convert cleanly; scanned PDFs need OCR with imperfect results. What a converter can and cannot give you, and how to get a good edit.

How to Scan Documents to PDF on Your Phone (Free, Private)

Turn camera photos of pages into a proper PDF: shoot pages that scan well, drag to reorder, set page size, margins and quality, merge batches, and keep everything on-device.

BMI: What It Measures and Where It Is Wrong

BMI is weight over height squared - a cheap screening proxy, not body fat or a diagnosis. Where it misleads: athletes, children, the elderly, pregnancy, and different ethnicities.

How to Calculate Age for Documents (Exact Years, Months and Days)

Age 'as of' a reference date, completed years, leap-day (Feb 29) birthdays, and unambiguous date formats for admissions, exams, visas and benefits paperwork.

Counting Business Days: Weekdays, Deadlines and the Long-Weekend Trap

Working-day math for contracts and delivery SLAs: exclude weekends, remember holidays are not built in, and handle the inclusive-versus-exclusive start-date off-by-one errors.

What a Valid Invoice Needs (and What Depends on Your Country)

The elements almost every invoice carries versus the jurisdiction-specific extras - tax/GST/VAT number, tax breakdown, e-invoicing, sequential numbering. A template is not tax advice.

Text-to-Speech for Accessibility: What It Helps and Its Limits

Browser TTS speaks text with the voices already on the device. Who it helps (low vision, dyslexia, proofreading), where it falls short, and why it complements rather than replaces accessible design.

Downloading and Using YouTube Thumbnails: What's Fair

You can grab a video's preview image, but usage rights are separate from the download button. Ownership, fair use, embedding versus re-hosting, and the safe rules - plus how the downloader actually works.

How to Convert HEIC to JPG on Windows (Free, and Without Uploading Your Photos)

Open iPhone HEIC photos on a PC: use a browser HEIC converter that decodes locally, or install the HEVC/HEIF extensions. What HEIC is, why Windows struggles, and when to convert.

LiftOff Badge PeerPush Badge