← All field guidesTraffic classification Ā· Protect demand

A strange User-Agent does not prove that a request is malicious

Privacy tools, accessibility technology, legitimate crawlers, and abusive automation can all produce unfamiliar identifiers.

Updated 2026-08-16 Ā· 5 min read
Written for
Finance, procurement, or privacy lead
Article format
Myth check
Take-away
myth-versus-reality table

The common belief

Privacy tools, accessibility technology, legitimate crawlers, and abusive automation can all produce unfamiliar identifiers.

The common belief for ā€œA strange User-Agent does not prove that a request is maliciousā€: Privacy tools, accessibility technology, legitimate crawlers, and abusive automation can all produce unfamiliar identifiers. You need an approval trail, a bounded liability, and records that collect no more data than necessary.

Why it sounds reasonable for ā€œA strange User-Agent does not prove that a request is maliciousā€: Renewal, cancellation, payment recovery, and privacy requests must remain auditable and self-service.

Why it sounds reasonable

Where it breaks for this case: Combine identity, repetition, requested path, cost, and customer outcome; treat Unknown as a request for more evidence, not guilt.

The evidence to use for ā€œA strange User-Agent does not prove that a request is maliciousā€: identify the evidence that would make this proposed action unsafe—Combine identity, repetition, requested path, cost, and customer outcome; treat Unknown as a request for more evidence, not guilt.

  • Evidence 1 for ā€œA strange User-Agent does not prove that a request is maliciousā€: Human/Bot/Unknown share
  • Evidence 2 for ā€œA strange User-Agent does not prove that a request is maliciousā€: requested path
  • Evidence 3 for ā€œA strange User-Agent does not prove that a request is maliciousā€: repetition and velocity
  • Evidence 4 for ā€œA strange User-Agent does not prove that a request is maliciousā€: orders and qualified inquiries

Where it breaks

A better operating rule for this exact problem: the acceptable end state must resolve the original condition—Privacy tools, accessibility technology, legitimate crawlers, and abusive automation can all produce unfamiliar identifiers.

myth-versus-reality table decision for ā€œA strange User-Agent does not prove that a request is maliciousā€: Combine identity, repetition, requested path, cost, and customer outcome; treat Unknown as a request for more evidence, not guilt.

The evidence to use

Build the myth-versus-reality table for ā€œA strange User-Agent does not prove that a request is malicious.ā€ Write the common belief, the conditions where it seems true, the counterexample, the evidence that resolves it, and the replacement operating rule.

A better operating rule

If ā€œA strange User-Agent does not prove that a request is maliciousā€ showed why a blunt stop can reject real demand, do not answer it with another blunt rule. Download the free plugin to establish a baseline, then use Pro Smart Protection when Human, Bot, Unknown, and revenue signals must shape control.

Next field guideProtection went live on Friday afternoon—and a customer function stopped →