How-to guide

How to check third-party cookies before consent

To check whether third-party cookies are set before consent, review cookies created before any recorded consent choice and identify which are associated with third-party services or non-essential purposes. CertScore.ai automates this by observing cookie timing, request context, and vendor evidence during public website scans. The output is a reviewable signal that helps teams compare live behavior with consent-platform and tag-manager configuration.

By CertScore.ai · Updated

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan

1. Start without a prior choice

Use a clean browser context and record page, region, browser settings, time, and capture window. Open Network and cookie storage before loading the page. Do not accept or reject during the baseline. Prior consent or privacy extensions can change the result.

2. Match storage to the request evidence

Record cookie name, domain, path, partition identity if present, lifetime, and when it appeared. Inspect Set-Cookie responses and requests carrying the cookie where available. Redact values. A third-party service can also use first-party storage, so domain ownership alone does not establish purpose.

A browser may block third-party storage. Record that limitation and review network activity too; no stored cookie does not mean no request or tracking behavior.

3. Classify and hand off

Combine the observed request and cookie with vendor purpose and the intended consent category. Technical cookies, uncertain classifications, missing timestamps, and unavailable frames need review rather than automatic conclusions.

Share the identity and timing with the CMP and tag-manager owner. Retest in fresh sessions after a change; compare an unchanged cookie separately from a new write or active transmission.

What CertScore.ai observes

CertScore.ai reviews cookie domains, names, vendor-like hosts, and consent timing to surface cookies that may deserve closer review.

The result is a business-facing review signal, not a conclusion about whether a cookie is allowed or prohibited.

Review caveats

Some cookies are technical, short-lived, or connected to a prior visitor state. Others may be set by embedded services whose purpose needs vendor documentation.

Use the observed evidence to check tag-manager rules, consent-platform categories, and vendor contracts before deciding what should change.

Run a free website behavior scan

Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.

Run a scan
CertScore.ai automated findings may contain errors. Always review the underlying evidence. CertScore.ai does not provide legal advice, certification, or compliance determinations.