Allow or block Reflectionbot on Cloudflare: AI Crawl Control, the managed robots.txt, and a custom rule

Open AI Crawl Control for the domain, find Reflectionbot in the Crawlers table and set its Action to Block. If it is not listed, add a custom rule that blocks requests whose user agent contains “Reflectionbot”.

This response

You are ClaudeBot (Anthropic). Citable recognised you as an AI agent, so this is https://getcitable.in/crawlers/reflectionbot/cloudflare with the UI removed — the content only. A browser asking for the same address gets the full designed page.

Reflectionbot, and where Cloudflare keeps the rule

Reflectionbot is a crawler run by Reflection. It reads pages at the moment a person asks a question, to answer it.

Cloudflare does not hold a site’s robots.txt; the origin does. But it can add to that file, and it can refuse a crawler before the origin is ever asked.

Step by step

What to paste

A group that names a crawler replaces the * group for that crawler; it does not add to it. Paths the * group closes are open to a crawler with its own group unless they are repeated there.

robots.txt at the origin, refusing Reflectionbot:

User-agent: Reflectionbot
Disallow: /

robots.txt at the origin, allowing Reflectionbot:

User-agent: Reflectionbot
Allow: /

What trips people up

The edge answers first. If Cloudflare blocks Reflectionbot, an Allow in robots.txt changes nothing: the crawler is refused before the origin is asked. A site that allows a crawler on paper and blocks it at the edge is a site that crawler never reads.

Asked, or actually refused?

Yes. A Block in AI Crawl Control or in a custom rule is answered by Cloudflare itself, and the request never reaches the origin. “Reflectionbot” is an ordinary word and “contains” would match it inside any user agent, so use the crawler’s own entry in AI Crawl Control rather than a custom rule.

Check it yourself

A 200 means the name is let through; a 403 means something in front of the page refuses it. This tests the name from your own address. A platform that checks a crawler’s address as well may treat the real Reflectionbot differently.

The request:

curl -I -A "Reflectionbot" https://your-site.example/

Questions

How do I block Reflectionbot on Cloudflare?

Open AI Crawl Control for the domain, find Reflectionbot in the Crawlers table and set its Action to Block. If it is not listed, add a custom rule that blocks requests whose user agent contains “Reflectionbot”.

How do I allow Reflectionbot on Cloudflare?

In AI Crawl Control set Reflectionbot to Allow, and check under Security → Settings that the AI bot setting is not blocking it.

Can Cloudflare actually stop Reflectionbot, or only ask it?

Yes. A Block in AI Crawl Control or in a custom rule is answered by Cloudflare itself, and the request never reaches the origin. “Reflectionbot” is an ordinary word and “contains” would match it inside any user agent, so use the crawler’s own entry in AI Crawl Control rather than a custom rule.

Does a rule for Reflectionbot affect Googlebot or my Google rankings?

No. Googlebot goes by its own name and follows its own rules; a group or a firewall rule for Reflectionbot does not apply to it.

Checked against Cloudflare's own documentation on 1 October 2026

Related

About Citable

Citable strips the UI from a website for AI agents and serves them only the content.

When an AI agent — ChatGPT, Claude, Perplexity or any of the 81 that Citable recognises — opens a page, Citable removes the theme, scripts, navigation and layout and serves only the content: the same facts, at the same URL, on the site's own domain. People and Google still get the full designed page.

How it works: https://getcitable.in/how-it-works · Summary for AI agents: https://getcitable.in/llms.txt


Source: https://getcitable.in/crawlers/reflectionbot/cloudflare · Citable · Run the free audit · llms.txt · getcitable@gmail.com