Checklist
Can I rely on CMP auto-blocking before Accept?
CMP auto-blocking is a claim that tags wait until Accept. Fresh and Reject visits show whether marketing hosts stayed quiet. Not a CMP install guide.
In brief
CMP auto-blocking, prior blocking, and automatic script blocking are vendor claims that tags wait until Accept. A cookie consent audit still checks cookies, storage, and network requests on Fresh, and whether Reject held. ConsentProbe can store those packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a CMP install guide and not legal advice.
Not legal advice
This FAQ explains how to treat CMP auto-blocking, prior blocking, and automatic script blocking as vendor claims about how tags are supposed to wait until Accept. It is not legal advice, not a CMP install tutorial, not a vendor review, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired on labeled Fresh and Reject visits. They do not say what counsel would allow.
Last updated September 27, 2026. The CMP claims guide owns the wider claims-versus-runtime method. The audit-versus-banner page positions an audit against a CMP. The before-Accept audit and the pre-consent checklist own the first load. The Reject leftovers guide owns a Reject failure. This page stays on the auto-blocking claim.
Short answer
CMP auto-blocking, prior blocking, and automatic script blocking are vendor claims that tags wait until Accept. A cookie consent audit still asks which cookies, storage entries, and network requests appeared on Fresh, before any Accept, and whether Reject held.
Treat the auto-block toggle and the CMP marketing copy as claims. Falsify them with clean Fresh and Reject captures. An auto-block switch that reads on does not prove marketing stayed quiet. ConsentProbe can produce Fresh and Reject packs with request, cookie, and screenshot links. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not turn auto-block on for you. Observation is not counsel permission. This page is not a CMP install guide, not a vendor review, and not legal advice.
What auto-blocking usually claims
Four claim surfaces get mixed when a dashboard says tags are blocked until Accept. Separate the copy from the request that appeared on Fresh. Write the finding as a marketing request on Fresh while auto-block was claimed on. Leave legal permission with counsel.
| Claim surface | What vendors often describe | What to verify at runtime |
|---|---|---|
| Auto-block or prior blocking toggle | Scripts or tags wait until a consent category is granted | Marketing hosts or IDs on Fresh before any Accept |
| Automatic script blocking | The CMP wraps or defers third-party tags | Hardcoded theme or app pixels still fire without that wrapper |
| Tags blocked until Accept | A container or a known vendor list is managed | GTM or another container still enqueues marketing tags on Fresh. The GTM guide is that check |
| Consent string or signal set | A choice recorded in storage or a TCF-style string | Marketing network still fires after Reject. The Reject leftovers guide and the Consent Mode page are those checks |
Bypass patterns a visit can show
Read each row as an observation type from Fresh or Reject. This page does not rank CMP products, and it does not invent a regional legal requirement. When an EU or California conclusion is the claim, use those regional paths. The free versus paid guide draws that line.
| Bypass pattern | What Fresh or Reject can show | Where to go next |
|---|---|---|
| GTM, or a similar container, still loads marketing tags | Tag or request fan-out on Fresh despite an auto-block claim | The GTM tags guide |
| Hardcoded theme, app, or plugin pixels | Direct pixel or SDK hosts outside the CMP-managed list | The before-Accept audit and the pre-consent checklist |
| Server-side or first-party collectors | A first-party path or an sGTM-style collector still receives events before Accept | The server-side GTM guide |
| A consent string or mode is set, and marketing still fires | Storage, Consent Mode, or a TCF-style signal is present, and ads hosts still hit after Reject | The Reject leftovers guide, the marketing-pixels FAQ, and the Consent Mode page |
| The banner looks blocked, and Network does not | The CMP screenshot claims control, and Network shows marketing IDs on Fresh | The audit-versus-banner page and the CMP claims guide |
Fresh and Reject on the storefront
These steps compare an auto-block claim with cookies and requests. They do not install a CMP, flip a prior-blocking toggle, or pick a vendor. The CMP claims guide holds the wider claims-versus-evidence frame. The Reject leftovers guide and the marketing-pixels FAQ hold a Reject failure. The audit-versus-banner page holds the case where banner confidence replaces the audit. The before-Accept audit and the pre-consent checklist hold the first-load method. The GTM guide holds container fan-out.
- Use a clean profile. Confirm the CMP or storefront claims auto-block or prior blocking is on. Screenshot that claim if it is visible.
- Load the storefront once. Do not click Accept.
- Capture cookies, storage, and Network. Label the pack Fresh.
- Open a new clean profile. Click Reject All, or the equivalent control. Navigate once more. Label the pack Reject.
- Compare the packs. Note any marketing, ads, or non-essential analytics hosts or IDs on Fresh, and whether the same hosts appear after Reject.
- Write one finding sentence per mismatch, such as a marketing host on Fresh while auto-block was claimed on. Tie the sentence to a request, a cookie, or a screenshot.
When theme pixels and containers get slow
Checking every theme pixel, container tag, and first-party collector by hand takes a long time when you also need host-level proof. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not turn auto-block on, does not install a CMP, and does not issue a certificate.
FAQ
Can I rely on CMP auto-blocking before Accept?
Treat auto-blocking as a claim. Verify with Fresh and Reject runtime evidence. The toggle alone does not show that marketing stayed quiet.
Does prior blocking or automatic script blocking mean tags stay off?
It means the vendor describes tags as waiting. Runtime still decides whether marketing hosts fired on Fresh.
If auto-block is on and Fresh is clean, am I done?
Fresh clean is useful evidence for that visit. Repeat Fresh after a theme, GTM, or CMP change. The CMP-switch retest page covers a vendor swap. Reject still matters when a Reject control exists.
Why can GTM still fire with auto-block claimed?
A container can enqueue marketing tags outside what the CMP wraps. The GTM tags guide is that check.
How is this different from CMP claims vs runtime?
That guide is the broad claims-versus-evidence frame. This FAQ answers the auto-blocking and prior-blocking question.
Is this legal advice?
No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to treat CMP auto-blocking as a claim and how to falsify it with Fresh and Reject. It is not legal advice, not a CMP install guide, not a vendor review, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the CMP claims guide for claims versus runtime, the Reject leftovers guide when Reject still tracks, the audit-versus-banner page when a banner stands in for an audit, and the before-Accept audit plus the pre-consent checklist for the first load. The GTM guide, the marketing-pixels FAQ, and the Consent Mode page cover common bypasses. The cookie notice page separates notice text from a choice mechanism. It is one neighboring page, alongside those checks.
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- Reject All Still Tracking: What to Check After You Say No
- What is the difference between a cookie consent audit and a cookie banner?
- Pre-Consent Cookie Audit: A Storefront Checklist
- Pre-consent audit checklist: what to verify before Accept
- Do Google Tag Manager tags fire before Accept?
- Does Reject All stop marketing pixels?
- Consent Mode v2 vs runtime cookie evidence: what still fires?
- What belongs in a cookie consent audit evidence pack?
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Do Server-Side GTM Tags Fire Before Accept?
- How to Retest After Switching CMP Vendors
- What is the difference between a cookie notice and cookie consent?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
Save a US-baseline technical record
After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.