The trap most origins are in
Behind a CDN, the IP check cannot run at all
Verification by address only works if your log holds the real client address. This origin sits behind Cloudflare, so nginx's $remote_addr is the Cloudflare edge, 104.22.x.x, and not the client. Checked against every vendor's published prefix file on 3 October 2026, that marks 100% of every family in this catalogue unverified, Googlebot included: 25,479 requests whose user agent said Googlebot, and 0 of them inside Google's 317 published prefixes.
That is not a finding about Google. It is a finding about the log. Until the real client address is restored, an origin behind a CDN cannot answer the identity question by address at all, whatever its prefix lists say. The fix is to read the forwarded address and write that one: Cloudflare's CF-Connecting-IP header, nginx's real_ip module, Apache's mod_remoteip. Do that before trusting any crawler verification you run on your own log, because an unverified result here means the log, not the crawler.
One number needs its own note. That 25,479 counts every request in the window whose user agent said Googlebot, and it includes this site's own audit sweeps, which wear a Googlebot user agent on purpose. The catalogue's Googlebot row reads 2,426 instead, because the reading excludes our own readbacks before it counts anything. The two figures measure different sets and both are stated here so neither reads as a correction of the other.