Scans may be included, in aggregate and de-identified, in published ConsentStack research. We never publish an individual site's results without permission. See our Privacy Policy.
Wondering how it stacks up? We ran 12 other cookie scanners against a test site with documented violations: see the tested comparison and the full reliability study.
Third-party trackers
Detects scripts from external domains including analytics, advertising, and social widgets.
Cookie analysis
Examines cookies set during page load, including expiration, security flags, and party classification.
Consent banner detection
Identifies which CMP you use (or flags the absence) and measures its load performance.
Pre-consent and post-Reject fires
The most common violation: trackers and cookies that fire before the visitor chooses, or keep firing after they click Reject.
Regulation coverage
Maps each finding to the laws that apply to your site: GDPR and ePrivacy for EU visitors, CCPA/CPRA for US visitors, plus any national law your domain points to, from a library of 195+.
Geo-variant behavior
Scans from EU and US servers to detect when your site behaves differently for visitors in different regions.
Common questions
Enter your domain above. The checker loads your site the way a visitor's browser does, from an EU and a US location, and clicks both Reject and Accept. It records every cookie and tracker that fires before the visitor makes a choice and every one that keeps firing after Reject, names the vendor behind each, and returns a score with a verdict for each region. That covers the part of GDPR a scanner can observe: consent for cookies and tracking. It cannot read your privacy policy, your processor contracts, or how you handle access requests, so treat a passing scan as one piece of the picture rather than a certificate.
Most free GDPR checkers list the cookies a page sets. The list is the easy part; regulators act on timing. This checker records what loads before consent, whether Reject actually stops analytics and advertising tags, whether the banner offers a real Reject option, and whether your site treats EU visitors (opt-in under GDPR and ePrivacy) differently from US visitors (opt-out under CCPA and CPRA). It also flags the opposite problem, blocking more than the law requires, which costs you analytics data with no compliance gain.
Not necessarily. The banner is the visible part; compliance is what happens underneath it. The most common failure we see is a banner that displays correctly while analytics and advertising tags fire on page load, before anyone has clicked, or keep firing after the visitor clicks Reject. GDPR and ePrivacy require prior consent for non-essential cookies, so a banner that does not gate the tags is a violation with a banner on top. Scan your site and read the pre-consent and post-Reject findings first; those are the two numbers that decide it.
Yes, when the site offers goods or services to people in the EU or monitors their behavior, which is what analytics and advertising cookies do. GDPR applies based on where your visitors are, not where your company is registered. That is why this checker scans from both an EU and a US location: the same site is expected to behave differently in each. US state laws such as California's CCPA and CPRA work the other way round, opt-out rather than opt-in, so the report grades each region against its own rule instead of applying one standard to both.
100+ happy customers
Ready to launch consent that feels built in?
Set up a modern compliance in minutes, block scripts before consent, and stay compliant across regions without enterprise pricing or sales calls.