检查清单

Can I rely on CMP auto-blocking before Accept?

开始免费审计

CMP auto-blocking is a claim that tags wait until Accept. Fresh and Reject visits show whether marketing hosts stayed quiet. Not a CMP install guide.

In brief

CMP auto-blocking, prior blocking, and automatic script blocking are vendor claims that tags wait until Accept. A cookie consent audit still checks cookies, storage, and network requests on Fresh, and whether Reject held. ConsentProbe can store those packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a CMP install guide and not legal advice.

Not legal advice

This FAQ explains how to treat CMP auto-blocking, prior blocking, and automatic script blocking as vendor claims about how tags are supposed to wait until Accept. It is not legal advice, not a CMP install tutorial, not a vendor review, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired on labeled Fresh and Reject visits. They do not say what counsel would allow.

Last updated September 27, 2026. The CMP claims guide owns the wider claims-versus-runtime method. The audit-versus-banner page positions an audit against a CMP. The before-Accept audit and the pre-consent checklist own the first load. The Reject leftovers guide owns a Reject failure. This page stays on the auto-blocking claim.

Short answer

CMP auto-blocking, prior blocking, and automatic script blocking are vendor claims that tags wait until Accept. A cookie consent audit still asks which cookies, storage entries, and network requests appeared on Fresh, before any Accept, and whether Reject held.

Treat the auto-block toggle and the CMP marketing copy as claims. Falsify them with clean Fresh and Reject captures. An auto-block switch that reads on does not prove marketing stayed quiet. ConsentProbe can produce Fresh and Reject packs with request, cookie, and screenshot links. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not turn auto-block on for you. Observation is not counsel permission. This page is not a CMP install guide, not a vendor review, and not legal advice.

What auto-blocking usually claims

Four claim surfaces get mixed when a dashboard says tags are blocked until Accept. Separate the copy from the request that appeared on Fresh. Write the finding as a marketing request on Fresh while auto-block was claimed on. Leave legal permission with counsel.

Auto-block claim surfaces, what vendors often describe, and what to verify at runtime.
Claim surfaceWhat vendors often describeWhat to verify at runtime
Auto-block or prior blocking toggleScripts or tags wait until a consent category is grantedMarketing hosts or IDs on Fresh before any Accept
Automatic script blockingThe CMP wraps or defers third-party tagsHardcoded theme or app pixels still fire without that wrapper
Tags blocked until AcceptA container or a known vendor list is managedGTM or another container still enqueues marketing tags on Fresh. The GTM guide is that check
Consent string or signal setA choice recorded in storage or a TCF-style stringMarketing network still fires after Reject. The Reject leftovers guide and the Consent Mode page are those checks

Bypass patterns a visit can show

Read each row as an observation type from Fresh or Reject. This page does not rank CMP products, and it does not invent a regional legal requirement. When an EU or California conclusion is the claim, use those regional paths. The free versus paid guide draws that line.

Bypass patterns Fresh or Reject can show, and the neighboring guide.
Bypass patternWhat Fresh or Reject can showWhere to go next
GTM, or a similar container, still loads marketing tagsTag or request fan-out on Fresh despite an auto-block claimThe GTM tags guide
Hardcoded theme, app, or plugin pixelsDirect pixel or SDK hosts outside the CMP-managed listThe before-Accept audit and the pre-consent checklist
Server-side or first-party collectorsA first-party path or an sGTM-style collector still receives events before AcceptThe server-side GTM guide
A consent string or mode is set, and marketing still firesStorage, Consent Mode, or a TCF-style signal is present, and ads hosts still hit after RejectThe Reject leftovers guide, the marketing-pixels FAQ, and the Consent Mode page
The banner looks blocked, and Network does notThe CMP screenshot claims control, and Network shows marketing IDs on FreshThe audit-versus-banner page and the CMP claims guide

Fresh and Reject on the storefront

These steps compare an auto-block claim with cookies and requests. They do not install a CMP, flip a prior-blocking toggle, or pick a vendor. The CMP claims guide holds the wider claims-versus-evidence frame. The Reject leftovers guide and the marketing-pixels FAQ hold a Reject failure. The audit-versus-banner page holds the case where banner confidence replaces the audit. The before-Accept audit and the pre-consent checklist hold the first-load method. The GTM guide holds container fan-out.

  1. Use a clean profile. Confirm the CMP or storefront claims auto-block or prior blocking is on. Screenshot that claim if it is visible.
  2. Load the storefront once. Do not click Accept.
  3. Capture cookies, storage, and Network. Label the pack Fresh.
  4. Open a new clean profile. Click Reject All, or the equivalent control. Navigate once more. Label the pack Reject.
  5. Compare the packs. Note any marketing, ads, or non-essential analytics hosts or IDs on Fresh, and whether the same hosts appear after Reject.
  6. Write one finding sentence per mismatch, such as a marketing host on Fresh while auto-block was claimed on. Tie the sentence to a request, a cookie, or a screenshot.

When theme pixels and containers get slow

Checking every theme pixel, container tag, and first-party collector by hand takes a long time when you also need host-level proof. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.

Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not turn auto-block on, does not install a CMP, and does not issue a certificate.

FAQ

Can I rely on CMP auto-blocking before Accept?

Treat auto-blocking as a claim. Verify with Fresh and Reject runtime evidence. The toggle alone does not show that marketing stayed quiet.

Does prior blocking or automatic script blocking mean tags stay off?

It means the vendor describes tags as waiting. Runtime still decides whether marketing hosts fired on Fresh.

If auto-block is on and Fresh is clean, am I done?

Fresh clean is useful evidence for that visit. Repeat Fresh after a theme, GTM, or CMP change. The CMP-switch retest page covers a vendor swap. Reject still matters when a Reject control exists.

Why can GTM still fire with auto-block claimed?

A container can enqueue marketing tags outside what the CMP wraps. The GTM tags guide is that check.

How is this different from CMP claims vs runtime?

That guide is the broad claims-versus-evidence frame. This FAQ answers the auto-blocking and prior-blocking question.

Is this legal advice?

No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.

Limits of this page

This page tells you how to treat CMP auto-blocking as a claim and how to falsify it with Fresh and Reject. It is not legal advice, not a CMP install guide, not a vendor review, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.

Related guides

Open the CMP claims guide for claims versus runtime, the Reject leftovers guide when Reject still tracks, the audit-versus-banner page when a banner stands in for an audit, and the before-Accept audit plus the pre-consent checklist for the first load. The GTM guide, the marketing-pixels FAQ, and the Consent Mode page cover common bypasses. The cookie notice page separates notice text from a choice mechanism. It is one neighboring page, alongside those checks.

Sources

These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.

保存一次美国基线技术记录

完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。

Accept 前的 CMP 自动拦截 | ConsentProbe