检查清单
How to audit third-party iframes and embedded YouTube before Accept
Audit third-party iframes and embedded YouTube that can set cookies before Accept without a top-level pixel. Fresh and Reject steps. Not an embed how-to.
In brief
A third-party iframe or an embedded YouTube player can set cookies or storage from the embed origin even when the top-level Network list shows no marketing pixel. List iframe sources on Fresh, capture embed-host requests and cookies, then repeat after Reject. A youtube-nocookie label still needs that check. ConsentProbe can store Fresh and Reject packs. A free US-baseline scan is not an EU or California legal conclusion. This page is not a YouTube embed how-to and not legal advice.
Not legal advice
This guide explains how to observe third-party iframes and embedded YouTube, and similar embeds, that set cookies or storage before Accept even when no top-level marketing pixel is present. It is not legal advice, not a YouTube embed how-to, and not a GDPR, ePrivacy, CPRA, or other compliance certificate. ConsentProbe reports are technical observations of what fired. They do not say what counsel would allow. Observation is not counsel permission.
Last updated September 28, 2026. The before-Accept audit owns the general first load. The first-party versus third-party guide owns party labels. The pre-consent checklist owns the pass order. The evidence-pack page owns how to file the captures. This page stays on iframe documents and embed hosts.
Short answer
Third-party iframes and embedded YouTube can set cookies or storage from the embed origin even when no top-level marketing pixel appears in Network. A cookie consent audit that only lists Meta, TikTok, or GA hosts can miss youtube.com, googlevideo, or other iframe documents that load on first paint. An empty top-level pixel list is a claim that embeds stayed cold. Falsify it on a clean visit.
List iframe sources on Fresh. Open each embed document's cookies and storage where the browser exposes them. Capture Network for those embed hosts. Repeat after Reject. Note fan-out that continues after the click. YouTube's embed help documents youtube-nocookie.com as the domain for privacy-enhanced mode. That label still needs the same Fresh check. Do not treat the label as a cold jar.
ConsentProbe can produce Fresh and Reject packs with request, cookie, and screenshot links. A free US-baseline scan is not an EU or California legal conclusion. ConsentProbe does not install a CMP and does not configure embeds. This page is not a YouTube embed how-to and not legal advice.
Why an iframe list is its own pass
A top-level pixel sweep and an iframe sweep answer different questions. Write the finding as a youtube.com cookie on Fresh, or the same embed host after Reject. Leave permission with counsel.
| Surface | What a browser test can see | Common miss |
|---|---|---|
| Top-level marketing pixel | Network rows and cookies on the main document | Treating that list as the whole story |
| Third-party iframe or YouTube embed | iframe src values, embed-host Network, and cookies or storage on the embed origin | Skipping embeds because the top-level pixel list looks empty |
| CMP marketing-off claim | A screenshot of the banner or the category label | Matching runtime, including iframe documents, on Fresh and Reject |
Fresh and Reject on the storefront
These steps compare a claimed quiet page with iframe sources, cookies, and requests. They do not paste an embed snippet, turn on privacy-enhanced mode, or block iframes. The before-Accept audit holds the general first load. The party-label guide holds first-party versus third-party names. The pre-consent checklist holds the pass order. The evidence-pack page holds how to file the captures.
- Use a clean profile. Load the storefront once. Do not click Accept.
- In Elements, list iframe src values, including YouTube and other third-party embeds.
- Capture Network for those embed hosts. Capture cookies and storage for the main document and, where the browser exposes them, for embed origins.
- Screenshot the banner and a redacted iframe list. Label the pack Fresh.
- Open a new clean profile, or clear storage. Click Reject All. Navigate once more.
- Recapture the iframe list, cookies, and Network. Label the pack Reject. Compare it with Fresh and, if you ran one, with an Accept control.
- Write one finding sentence per mismatch, such as a youtube.com cookie on Fresh, or the same embed host after Reject.
YouTube labels still need a Fresh capture
A standard youtube.com embed and a privacy-enhanced or nocookie embed both need Fresh observation. YouTube's help page describes privacy-enhanced mode as a domain change to youtube-nocookie.com, aimed at how views feed later YouTube personalization. That description is not a measurement of your cookie jar. Capture the src you loaded and the cookies or requests that followed.
Autoplay, a thumbnail facade, or a consent-gated placeholder changes what loads on first paint. Record the iframe that actually loaded. A theme that intended to wait is a claim until Fresh shows a cold list.
This page does not walk through YouTube Studio or an iframe snippet. The question to falsify is whether an embed host or an embed-origin cookie appeared on Fresh or after Reject. Maps, chat widgets, and other video players use the same iframe list and the same Fresh and Reject labels.
Example, not a customer capture: Fresh Elements lists an iframe whose src is www.youtube.com/embed, and Application shows a cookie on youtube.com, while the top-level marketing-pixel filter is empty. That is a finding about the embed. It does not show that a pixel tag was absent from every other template.
When checking embed origins gets slow
Checking iframe origins across templates and product pages by hand takes a long time. ConsentProbe runs Fresh and Reject on the storefront URL. Each finding stays tied to a request, a cookie, or a screenshot.
Use the free US-baseline visit when you want the report format. Use paid EU or California scenarios when those regions are the claims. The free versus paid guide draws that line. ConsentProbe does not install embeds, does not install a CMP, and does not issue a certificate.
FAQ
How to audit third-party iframes and embedded YouTube before Accept
List iframe sources on a Fresh visit, capture embed-host Network and cookies, then repeat after Reject. YouTube embeds can set cookies. Verify that on Fresh rather than assuming the top-level pixel list is complete.
Do YouTube embeds set cookies before Accept?
They can. Verify iframe sources, embed-host Network, and cookies on a Fresh visit before you treat a quiet pixel list as proof.
If no marketing pixel appears, can embeds be skipped?
No. An iframe can set cookies or storage when the top-level pixel list is empty.
Does privacy-enhanced or nocookie YouTube skip the check?
No. Run Fresh anyway. A youtube-nocookie label is not a cold jar.
What if Reject All still loads the embed?
Treat it as a Reject failure. The Reject leftovers guide is the network check. Keep the evidence pack.
Will this page teach YouTube embed setup?
No. This page is a Fresh and Reject check, not a YouTube embed how-to.
Is this legal advice?
No. These are technical observations. Observation is not counsel permission. ConsentProbe does not replace counsel, and it does not install a CMP.
Limits of this page
This page tells you how to list iframe sources, capture embed-host requests and cookies on Fresh, and repeat the check after Reject. A missing top-level pixel does not prove embeds stayed cold. It is not legal advice, not a YouTube embed how-to, and not a certificate. Observation is not counsel permission. ConsentProbe reports stay tied to requests, cookies, and screenshots. A free US-baseline scan is not an EU or California legal conclusion.
Related guides
Open the before-Accept audit for the general first load, the party-label guide for first-party versus third-party names, the pre-consent checklist for the pass order, and the evidence-pack page for how to file the captures.
- How to run a cookie audit before Accept
- First-party vs third-party cookies before consent: what should you check?
- Pre-consent audit checklist: what to verify before Accept
- What belongs in a cookie consent audit evidence pack?
- Reject All Still Tracking: What to Check After You Say No
- What does a free US-baseline cookie audit prove vs paid EU or California scans?
- Cookie audit hub: which consent test should you run first?
- CMP claims vs runtime evidence: how do you prove the banner actually works?
- ConsentProbe methodology
- Pricing and listed regional products
Sources
These links cover the platform and regulatory context used in this guide. Applicability still depends on the organization and jurisdiction.
保存一次美国基线技术记录
完成自行检查后,可以跑一次免费美国基线审计:在加州以外做一次浏览器访问,把 Cookie、请求和截图存成证据。这次访问不会跑欧盟拒绝/接受,也不会跑加州 GPC。欧盟、加州和 Global 2 可在登录后的账单页购买。