What does your site load before anyone consents?

Enter a public address. We load it in a fresh browser without making a choice and report the third-party requests and storage observed on the sampled pages.

Consent: none given

We open the page as a first-time visitor would, decline nothing and accept nothing, then list what it loaded. No account needed.

What it looks for

More than a list of cookies.

  • Third parties contacted

    Third-party requests observed on the sampled pages before a choice, attributed where catalogue, filter-list or DNS evidence matches.

  • Cookies set before consent

    Cookies observed in this browser run, including first-party names that the catalogue associates with known services.

  • Disguised trackers

    Site subdomains whose DNS CNAME points to a known service. The result shows the target so you can inspect the actual request.

  • Your consent platform

    Which recognised banner appears, and whether its IAB interface returned a consent state before the scanner made a choice.

  • Recording and fingerprinting

    Known session-recording loaders and canvas readback patterns that need purpose-specific review, including possible security uses.

  • Bot protection

    If the site refuses automated browsers, the result names the protection instead of reporting a clean site.

How it works

The same visit your first customer makes.

  1. A first visit, in a real browser

    Chromium opens your page as a new visitor: no cookies, no earlier choice, and nothing clicked on your banner.

  2. It waits, scrolls and follows links

    It lets the page settle, moves the pointer and scrolls so delayed tags load, then visits up to two more pages on your site.

  3. Everything named, with the reason

    Each attribution includes its basis. Unknown and filter-list matches remain candidates for you to verify rather than definitive vendor findings.

Questions

What people ask before they trust a result.

Is the check free?

Yes. It needs no account and asks for nothing but the address of the page to check.

Does it change anything on my site?

No. It visits public pages the way a first-time visitor does. It never answers your banner, fills in a form or signs in.

Why does my own browser show something different?

What a site loads depends on where the visitor is, their device and their earlier choices. The check is a first visit from one location, which the result names, in a browser with no history.

Is this a compliance audit?

No. It reports what the sampled pages and interactions exposed before the scanner made a choice, with evidence-based candidate attributions. Whether an item must wait, be disclosed or support an opt-out depends on its exact purpose, configuration, jurisdiction and your arrangements with the provider.

My site blocked the check. What now?

Some bot protection refuses automated browsers, and the result says which one. Try a page that is not behind the protection, or allow the check through it.

How often should I check?

After any change to your tags, theme or apps. StrongPrivacy runs this check for you on a schedule, weekly or daily depending on the plan, and keeps the evidence.

After the check

Hold them back, then prove it, on every visit.

StrongPrivacy withholds the managed adapters and custom scripts you configure until their category is allowed, records the choice, and can run configured verification journeys before a choice, after rejection, after approval and after withdrawal.