xmarksfetch

Bot User-Agent: xmarksfetch

🤖 Overview

xmarksfetch is a web crawler operated by LastPass (originally Xmarks, formerly Foxmarks) to synchronize browser bookmarks across devices and platforms. Its primary purpose is fetching bookmark data from users' accounts to ensure consistency across multiple browsers and operating systems. The service launched in 2006, was acquired by LastPass in 2010, and the crawler continues to support legacy Xmarks users and LastPass bookmark sync features as documented in LastPass help pages and the Xmarks Wikipedia article.

🌐 Technical Behavior

The crawler performs periodic HTTP/HTTPS GET requests to designated synchronization endpoints, typically every 5‑15 minutes or triggered by user actions. It uses conditional requests with If-Modified-Since and If-None-Match headers to minimize data transfer. IP addresses are drawn from LastPass’s cloud infrastructure, including AWS ranges (e.g., 54.239.0.0/16) and Google Cloud Platform (e.g., 35.190.0.0/16) as listed in public ASN records. The User‑Agent string is documented as XmarksFetch/1.0 (case‑sensitive) and may also appear as Xmarks Sync. It follows standard HTTP redirects, supports gzip compression, and uses HTTP/2 when available. It does not crawl arbitrary websites but only user‑specific sync endpoints under *.xmarks.com or *.lastpass.com after authentication, typically via OAuth tokens.

📋 robots.txt Compliance

Per archived Xmarks help pages and LastPass documentation, xmarksfetch respects robots.txt directives when accessing any publicly accessible URLs. It obeys Disallow and Crawl‑Delay directives to avoid server strain. On authenticated private endpoints, robots.txt is not applicable as those URLs are user‑specific and not publicly indexed.

🔍 Detection Indicators

The primary detection method is the User‑Agent string XmarksFetch/1.0 or Xmarks/1.0. Behavioral fingerprints include recurrent requests from a fixed set of IP addresses over short intervals, often with a consistent pattern of GET requests to /api/sync or /bookmarks endpoints. Additional identifying headers may include a custom X‑Xmarks‑Version header. Log entries show repeated requests from the same IP range within minutes, a pattern noted in server administration forums.

📊 Data Usage

Collected bookmark data is used exclusively for syncing bookmarks across the user’s devices via LastPass or Xmarks. No data is used for AI training, advertising, or third‑party analytics. Data is encrypted in transit using TLS 1.2+ and at rest, following LastPass’s privacy policy and security practices. The crawler does not store or share data beyond what is necessary for synchronization, as confirmed in the Xmarks privacy policy.

⚙️ Rate Limiting Policy

Although legitimate, xmarksfetch can be aggressive during initial sync or after large bookmark changes, making rate limiting advisable. Administrators may apply threshold‑based throttling at e.g., 10 requests per second per IP to prevent resource exhaustion, following standard web server guidelines for crawler management.

⚠️

Your Site May Be Hemorrhaging Revenue to Bots

Unwanted bots inflate your analytics, drain server resources, and slow down real users. Check if your site is affected — completely free.

Check My Site for Free

Free to start  ·  Cancel anytime

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.