Tracker library

Adobe Experience Cloud: what it is, what it sets, and how to gate it.

An enterprise suite rather than one tracker: Analytics, Target, Audience Manager and the tag system, with a cookie footprint that spans several domains.

Vendor
Adobe
Scanner category
mixed
Consent category
Per Adobe product and purpose
Control
Custom script or container tag

What it is

Adobe Experience Cloud is a suite, not one tracker. The catalogue separates Analytics collection endpoints as analytics, Audience Manager and advertising endpoints as advertising, and Adobe Tags as a tag manager. Target and other personalisation uses need their own purpose analysis.

Because the tag system (adobedtm.com) can load any of the others, an Adobe site has the same problem as a tag-manager site: the loaded set is not visible in your repository.

What a scan matches

A verification scan drives a real browser and records the outbound requests observed during its configured journeys, so Adobe Experience Cloud is identified by request hosts and paths rather than by source-code claims. Requests on unvisited paths, after unperformed interactions or solely on the server remain outside that observation.

  • omtrdc.net: Adobe Analytics collection
  • demdex.net: Audience Manager identity
  • everesttech.net: advertising
  • adobedtm.com: Adobe tag delivery
  • 2o7.net: legacy Analytics collection

Cookies are classified by name before domain because many analytics and advertising tags write first-party cookies through the page, which places a vendor-related identifier on your domain. Matching known names helps attribute those values without assuming that every first-party cookie came from your own application.

CookieWhat it is for
AMCV_*, AMCVS_*Experience Cloud visitor identifiers
s_cc, s_sq, s_vi, s_fidAdobe Analytics cookies
mboxAdobe Target personalisation state

Controlling it with consent

No named adapter. In practice the control point is Adobe’s own tag property, where each extension can be conditioned on a consent state, combined with a custom script declaration for the loader itself.

Adobe supports its own consent signalling. As with any vendor-native mechanism, decide which system owns the decision and make the other one follow it rather than running both.

No named adapter: choose the appropriate control

The product ships named adapters for Google Tag Manager, Google Analytics, the Meta and TikTok pixels, and Klaviyo. Choose the control route that fits this technology: a custom HTTPS script declaration for a browser loader, an individual consent condition inside a tag manager, a platform or app setting, or a click-to-load placeholder for a frame. Server-side integrations need their own enforcement because a browser runtime cannot stop them.

What breaks if it is refused: personalisation and audience segmentation for refusing visitors, and Analytics reporting if it shares the same identity service.

Verifying it

Before consent there should be no request to demdex.net or omtrdc.net and no AMCV_ or mbox cookie. Personalisation via Target is the one most likely to be treated as necessary by a stakeholder. Settle that argument before the scan, not during it.

  • Before a choice: optional tracking endpoints and optional identifiers are absent; any intentionally loaded necessary or functional surface matches the control model described above
  • After rejecting optional categories: optional activity remains absent and the refusal persists across a reload
  • After granting the relevant category: the expected loader or embed appears and the feature behaves normally
  • After withdrawing: new optional activity stops; where the vendor supports a consent signal, verify that the signal is sent as well as checking network behavior

Common questions

Is Adobe Analytics advertising or analytics?

Its collection endpoints are classified as analytics. If the implementation also uses Audience Manager, advertising, Target or a shared identity for additional purposes, classify and control those components separately instead of inheriting one category from the suite name.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.