Skip to content
Glossary

Honeypot link

A honeypot link is a link placed on a page so that a person will never follow it, in order to identify clients that follow every link they parse.

A honeypot link is a link placed on a page so that a person will never follow it, in order to identify clients that follow every link they parse. The trap costs the site almost nothing and catches naive crawlers immediately.

#How they are hidden

  • Styled away with display:none, visibility:hidden, zero dimensions or opacity.
  • Positioned off-screen with a large negative offset.
  • Rendered in the background colour, or placed behind another element.
  • Listed in robots.txt as disallowed, then linked from the page. Following it proves two things at once.

The last of these is the most informative to the site, because a compliant crawler had explicit instructions not to go there. It is also the easiest to avoid.

#Why hidden does not mean trap

Plenty of legitimate links are invisible. Skip-navigation links are hidden until focused, precisely so keyboard and screen-reader users can jump past a menu, and WCAG-conformant sites use that pattern deliberately. Treating every off-screen link as a trap will make you skip real navigation on accessible sites.

The distinguishing question is not whether a link is invisible but whether a person could reach it. A link revealed on focus is navigable; one with no path to visibility for any user is not.

#Avoiding them

Follow links from a rendered page rather than from raw markup, and check the computed style and the element’s position at the point you decide. A headless browser gives you that for free; an HTML parser does not, and this is one of the real differences between the two approaches.

Honour robots.txt as a matter of course. It removes an entire class of trap and costs you pages you were not entitled to fetch anyway.

#Commonly confused with

A CAPTCHA asks a visitor to prove something. A honeypot asks nothing and gives no feedback: the page returns normally and the classification happens elsewhere, which is why the effect often appears much later as an unexplained decline in success rate.

Frequently asked questions

How do I detect a honeypot link before following it?
Render the page and inspect the computed style and geometry of the anchor rather than reading the markup. Zero size, hidden visibility, a large negative offset or text matching the background all warrant skipping. Cross-check the target path against robots.txt, since traps are often disallowed there.
Are all invisible links traps?
No, and assuming so will break real navigation on accessible sites. Skip-navigation links are deliberately hidden until they receive keyboard focus, as a documented accessibility pattern, and some menus hide their contents until opened. The useful test is whether any user could reach the link, not whether it is visible in the default state.
What happens when my crawler follows one?
Usually nothing visible. The page returns normally and the classification is recorded elsewhere, so the consequence arrives later as blocks, challenges or degraded content. That silence is the point: immediate feedback would tell you which link to avoid next time.

Sources

  1. RFC 9309: the Robots Exclusion Protocol, whose disallowed paths often mark traps
  2. W3C WCAG 2.2: why legitimate links are sometimes hidden from sighted users

Related terms