All crawlers

Meta · Other AI

facebookexternalhit

A URL shared into a Facebook post, a Messenger thread or a Facebook social plugin brings this within seconds to build the card the recipient will see; Meta says it “gathers, caches, and displays” the title, description and thumbnail. The description is narrow and unchanged across every capture (link previews plus security and integrity checks such as malware scanning), and Meta does not say this token performs AI fetching, attributing that work to the three `meta-*` tokens instead, so treat any claim that it feeds a model as unsourced. It is the only Meta crawler with published operational requirements, which tells you how tight the loop is: gzip or deflate, Open Graph tags inside the first 1 MB, a response within a few seconds, and a `Range: bytes=0-524288` header your server must honour or ignore cleanly. Meta names Facebook, Instagram and Messenger as the sharing surfaces; WhatsApp previews are widely attributed to this agent but Meta does not name WhatsApp, so treat that coverage as unconfirmed.

Operated by
Meta
Purpose
Other AI

AI-adjacent traffic that does not fit the three purposes above.

robots.txt token
facebookexternalhit
Verification
Network origin only

How to verify facebookexternalhit

We hold no list of IP addresses that Meta publishes itself for facebookexternalhit. What we hold instead is 574 prefixes that a third party (a public routing record, not Meta) reports Meta's network announcing. A request from inside one of those tells you where it came from, not who sent it: anything else on that network can send the same packet, and nothing we hold ties facebookexternalhit to those addresses beyond the network they sit on. A request from OUTSIDE them is not thereby a fake either: this describes one network's announcements, not every address Meta can crawl from. Corroboration, not proof.

We hold no range list Meta publishes itself for facebookexternalhit, so there is no such fetch to confirm. This entry was last reviewed against Meta's own documentation on .

User agent

Meta publishes this user agent for facebookexternalhit. Match on the facebookexternalhit product token rather than the whole string: vendors revise the surrounding version and URL fragments without notice.

facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)

robots.txt for facebookexternalhit

Mostly, with a stated security carve-out: “the FacebookExternalHit crawler might bypass robots.txt when performing security or integrity checks, such as checking for malware or malicious content.” A `Disallow` suppresses preview crawling but is not a guarantee of zero requests.

Block

User-agent: facebookexternalhit
Disallow: /

Allow

User-agent: facebookexternalhit
Allow: /

robots.txt is a request, not an enforcement mechanism. It is honoured by convention, and a crawler that ignores it is stopped at your edge, not in a text file.

What blocking facebookexternalhit costs you

The most visible failure in this directory and the one your marketing team notices within a day: every link to your site shared on Facebook, Instagram or Messenger renders as a bare URL (no headline, no image, no description) on posts you did not write and cannot edit after the fact. Meta caches, so a bad crawl persists until somebody forces a re-crawl through the Sharing Debugger. Two documentation defects belong on the same page: the companion UA `facebookcatalog/1.0` was listed in both the 2025 and January 2026 captures and has been dropped from the current one with no deprecation note, and the page's own advice to allow-list “the IP addresses (more secure)” links to an `#identify` anchor whose section Meta deleted: the docs now recommend verification guidance that no longer exists.

Vendor documentation

Other Meta tokens we track