Checklist

Does a cookie audit catch tracking pixels?

Start a free audit

A cookie audit catches tracking pixels when it records Network and storage, not cookie names alone. Fresh and Reject. Not a second hub. Not legal advice.

In brief

A cookie audit catches tracking pixels when it records Network hosts and related storage, not only cookie names. Many marketing pixels set cookies. Some fire as request-only pixels with little or no durable cookie. A pack that never lists those hosts on Fresh and Reject has not observed the pixel surface. ConsentProbe can store both packs. A free US-baseline scan is not an EU or California legal conclusion. This FAQ is not a second cookie-audit hub and not legal advice.

Not legal advice

This FAQ explains how to observe whether a cookie audit includes tracking-pixel surfaces: cookies, storage, and Network requests to pixel hosts on Fresh and Reject visits. It is not legal advice, not a ruling that any pixel was caught, allowed, or blocked as a legal matter, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired under labeled visits. They do not say what counsel would allow. Observation is not counsel permission.

Last updated September 30, 2026. The before-Accept audit owns the protocol. The testing hub owns which test is next. The marketing-pixels FAQ owns whether Reject stopped a marketing pixel. The evidence pack owns the handoff file. Meta Pixel and CAPI owns one named browser-plus-server example. The label page compares the words cookie audit and pixel audit. This FAQ only answers whether pixels are in cookie-audit scope. It does not open a second cookie-audit hub.

Short answer

Yes, as an observation, when the audit records Network and storage as well as cookies. A cookie-table-only pack misses request-only pixels. Request-only pixels are still pixel surfaces. Fresh and Reject both matter, because one unlabeled visit cannot show whether Accept or Reject changed the host.

Treat we ran a cookie audit as incomplete if the pack never lists facebook, meta, tiktok, or similar hosts, or their first-party aliases, on Fresh and Reject. The before-Accept audit, the marketing-pixels FAQ, the Meta guide, the hub, and the evidence pack own the neighboring jobs. This FAQ is not a second cookie-audit hub, and it is not the label comparison. It is not legal advice. Observation is not counsel permission.

What catch means

Catch here means the pack recorded the surface. Prefer a sentence such as Fresh Network shows host X. Leave the legal reading with counsel. The next page compares the labels cookie audit and pixel audit. This page stays on surfaces.

Cookie, storage, and Network surfaces a cookie audit can record. Technical labels, not a legal category for pixels.
SurfaceOften showsMisses if you only…
Cookie tableNamed IDs from some pixelsYou ignore Network
Storage (local and session)SDK keys some pixels writeYou export a cookie table only
Network (pixel hosts)Request-only pixels. Server CAPI is usually out of bandYou never open DevTools Network
Fresh versus Reject labelsWhether Accept or Reject changed the surfaceYou keep one unlabeled visit

Request-only pixels

A tracking pixel can fire without setting a named cookie. The request still leaves the browser. If the report lists cookie names and stops, that request is absent from the pack even when Network showed a marketing host on Fresh. An empty cookie delta does not retire the host row.

Server paths such as Meta CAPI stay mostly out of DevTools. When the host is Meta or Facebook, open the Meta Pixel and CAPI guide for the browser-versus-server split. This FAQ does not repeat that guide.

What to capture

These steps name the three surfaces. They do not replace the before-Accept audit.

  1. Use a clean profile. Load the storefront once. Do not click Accept. Label the pack Fresh.
  2. Record cookies, storage, and Network rows to known marketing or analytics hosts. Meta, TikTok, LinkedIn, and Attentive-class hosts are examples only.
  3. Open a new clean profile. Click Reject All. Navigate once. Label the pack Reject. Recapture the same three surfaces.
  4. Write one finding sentence per unexpected host or cookie, such as a pixel host on Fresh, or the same host after Reject.
  5. Hand engineering an evidence pack when the rows need an owner. Open the hub for which test is next. Open the Meta guide when the host is Meta or Facebook.

When a cookie-name PDF gets slow

A cookie-name PDF alone misses request-only pixels. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install or block pixels, does not install a CMP, and does not issue a certificate. A free US-baseline scan is not an EU or California legal conclusion.

FAQ

Does a cookie audit catch tracking pixels?

When it records Network and storage as well as cookies, yes as an observation. A cookie-table-only pack misses request-only pixels.

Can a tracking pixel fire without setting a cookie?

Yes. Check Network on Fresh and on Reject. An empty cookie delta does not retire the host row.

Is this the same as whether Reject All stops marketing pixels?

No. The marketing-pixels FAQ answers whether Reject stopped them. This FAQ answers whether pixels are in cookie-audit scope.

Does this replace the Meta Pixel and CAPI guide?

No. That guide is the named-tool check for browser Meta plus server CAPI. This FAQ is about scope.

Is this a second cookie-audit hub?

No. The hub stays the testing hub. This FAQ only answers pixel surfaces inside a cookie audit.

Is this legal advice?

No. These are technical observations. It is not legal advice. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This FAQ says a cookie audit catches tracking pixels when the pack includes Network and storage, not cookie names alone. It is not legal advice, not a second cookie-audit hub, and not the page that compares cookie-audit and pixel-audit labels. Observation is not counsel permission. ConsentProbe does not install or block pixels, and it does not install a CMP. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the before-Accept audit for the protocol, the hub for which test is next, the marketing-pixels FAQ when Reject is the question, the evidence pack for the handoff, and Meta Pixel and CAPI for the named browser-plus-server example.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

Save a US-baseline technical record

After a DIY check, run a free US-baseline audit: one browser visit outside California, with cookies, requests, and screenshots stored as evidence. That visit does not run EU reject/accept or California GPC. EU, California, and Global 2 audits can be purchased from Billing after sign-in.

Does a Cookie Audit Catch Tracking Pixels? | ConsentProbe