I did this to Google for a while only to have my domains listed as malicious. I did not offer any malicious material, just different content for search engines was enough to flag my sites. They also did this to me when I gave google different IP addresses using a split DNS view. This was a while back so maybe they stopped this, I honestly don't know. Now I just give them and most bots a password prompt. Google and most bots can't speak HTTP/2.0 yet. Bing is the exception and I just trust user-agent for them.
# all nginx virtual sites
if ($server_protocol != HTTP/2.0) { return 302 https://auth.domain.tld$request_uri; }
# in auth.domain.tld virtual site
auth_delay 4s;
location / { auth_basic "Wamp Wamp"; auth_basic_user_file /dev/shm/.p; }