zoomspider
Crawler User-Agent:zoomspider
🤖 Overview
ZoomSpider is a legitimate web crawler operated by ZoomInfo Technologies Inc. (formerly DiscoverOrg), a publicly traded B2B data intelligence company headquartered in Vancouver, Washington, USA. Its primary purpose is to systematically collect publicly available business contact information—such as email addresses, job titles, company names, and phone numbers—from corporate websites, press releases, news archives, and professional social networks. This data feeds into ZoomInfo’s flagship Intent Data and Contact Database products, which are sold to sales and marketing teams for lead generation and account-based marketing. The bot was first documented in public user-agent lists around 2016 and has since become one of the most well-known “business intelligence crawlers” alongside similar bots from LeadIQ and Lusha.
🌐 Technical Behavior
ZoomSpider typically initiates crawling sessions from a pool of IPv4 addresses registered to ZoomInfo’s own ASN (AS395791 – ZoomInfo Technologies Inc.), with ranges that frequently include 64.124.x.x and 208.70.x.x subnets. It performs HTTP/1.1 GET requests at a moderate to high frequency, often sending up to 20–30 requests per minute per source IP, though the rate can spike during bulk re‑crawls of large domains. The crawler does not fetch images, CSS, or JavaScript files; it targets only HTML pages and commonly parses mailto: links, meta tags, and visible text containing email patterns. It respects gzip encoding and will follow internal redirects (301/302) but does not appear to execute JavaScript. According to independent webmaster observations, the bot typically runs between 08:00 and 20:00 UTC, aligning with North American business hours, and it avoids crawling on weekends or major holidays. The default request header includes a Referer field set to the root URL of the site being crawled, and it accepts all common content types (text/html, application/xhtml+xml).
📋 robots.txt Compliance
ZoomInfo officially states that ZoomSpider adheres to the robots.txt exclusion standard, as documented in their Web Crawler Policy page (available at https://www.zoominfo.com/crawlpolicy). The bot reads the Disallow directives before each crawl session and will cease crawling any path or directory that is explicitly forbidden. However, several webmaster forum posts (e.g., on WebmasterWorld and Stack Exchange) note that the bot occasionally ignores Crawl-Delay directives, especially when running at full speed. ZoomInfo encourages site owners to block specific subdirectories using User-agent: ZoomSpider followed by Disallow: /private/ for fine‑grained control.
🔍 Detection Indicators
The standard user‑agent string is ZoomSpider (https://www.zoominfo.com/about/zoominfo-crawler/) or simply ZoomSpider/1.0. A secondary variant sometimes appears as ZoomInfo Crawler or ZoominfoBot. Additional fingerprinting clues include a missing Accept‑Language header, a Connection: close header nearly every request, and a User‑Agent that always contains the substring “Zoom”. The bot also sends a custom header X‑ZoomInfo‑Crawler: 1 on some requests, as observed in server logs from Hacker News discussions. The IPs consistently resolve to the zoominfo.com domain via reverse DNS (e.g., crawler.zoominfo.com).
📊 Data Usage
All data collected by ZoomSpider is ingested into ZoomInfo’s proprietary Contact Database, which is updated in near‑real time and offered as a subscription service to over 35,000 customers. The extracted contact details are enriched with firmographic data (company size, industry, revenue) and used to power sales intelligence tools, such as ZoomInfo’s Chrome extension and CRM integrations. The company explicitly states in its privacy policy that only publicly available information is stored, and that the crawler does not scrape password‑protected or login‑gated content.
⚙️ Rate Limiting Policy
ZoomSpider is rate‑limited because its aggressive crawling cadence—often multiple requests per second—can degrade server performance for small to medium‑sized websites. The recommended threshold‑based blocking approach is to set a limit of 10 requests per minute per IP from the ZoomInfo range, with a 429 Too Many Requests response if exceeded, which aligns with industry best practices for preserving site availability while still permitting legitimate business intelligence gathering.
Similar Threats
Free Bot Analysis
Is Your Site Under Bot Attack Right Now?
Find out exactly how much of your traffic is automated — and which bots are draining your bandwidth and skewing your analytics.
Run Free Bot Scan →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.