How to check third-party cookies before consent
To check whether third-party cookies are set before consent, review cookies created before any recorded consent choice and identify which are associated with third-party services or non-essential purposes. CertScore.ai automates this by observing cookie timing, request context, and vendor evidence during public website scans. The output is a reviewable signal that helps teams compare live behavior with consent-platform and tag-manager configuration.
By CertScore.ai · Updated
Run a free website behavior scan
Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.
1. Start without a prior choice
Use a clean browser context and record page, region, browser settings, time, and capture window. Open Network and cookie storage before loading the page. Do not accept or reject during the baseline. Prior consent or privacy extensions can change the result.
2. Match storage to the request evidence
Record cookie name, domain, path, partition identity if present, lifetime, and when it appeared. Inspect Set-Cookie responses and requests carrying the cookie where available. Redact values. A third-party service can also use first-party storage, so domain ownership alone does not establish purpose.
A browser may block third-party storage. Record that limitation and review network activity too; no stored cookie does not mean no request or tracking behavior.
3. Classify and hand off
Combine the observed request and cookie with vendor purpose and the intended consent category. Technical cookies, uncertain classifications, missing timestamps, and unavailable frames need review rather than automatic conclusions.
Share the identity and timing with the CMP and tag-manager owner. Retest in fresh sessions after a change; compare an unchanged cookie separately from a new write or active transmission.
What CertScore.ai observes
CertScore.ai reviews cookie domains, names, vendor-like hosts, and consent timing to surface cookies that may deserve closer review.
The result is a business-facing review signal, not a conclusion about whether a cookie is allowed or prohibited.
Review caveats
Some cookies are technical, short-lived, or connected to a prior visitor state. Others may be set by embedded services whose purpose needs vendor documentation.
Use the observed evidence to check tag-manager rules, consent-platform categories, and vendor contracts before deciding what should change.
Related CertScore.ai pages
Run a free website behavior scan
Scan cookies, trackers, CMPs, consent, privacy policy, GDPR, CCPA, TLS, accessibility, and other public-web risk signals.
