Privacy check: what does your site load before consent?

Enter a domain. The check loads the home page and lists every third party that is fetched on the first visit – before the visitor clicks anything. Google Fonts from foreign servers and active tracking scripts are the two findings that regularly lead to warning letters in Germany.

Why Google Fonts are a problem

Embedding fonts directly from fonts.googleapis.com sends the visitor’s IP address to Google on every page view, without consent. In 2022 the Munich Regional Court saw this as a violation of personality rights (case 3 O 17493/20) and awarded damages. Waves of warning letters followed. The fix is simple: download the fonts and serve them from your own server. The check also recognises other font services such as Adobe Fonts.

Tracking before consent

Analytics, pixels and tag managers may only load after the visitor has consented. A consent banner alone is not enough: what matters is that the script does not run before consent. The check reads the delivered HTML and sees whether a script is embedded actively or blocked by a consent manager (for example via type="text/plain" and data-cookieconsent). Blocked services are listed as information, active ones as a warning.

What the check sees – and what it does not

The check reads the HTML the server delivers, without executing JavaScript. Whatever a tag manager loads later is therefore invisible – but the tag manager itself is already a tracking script and is reported as one. Cookies are not counted: they only appear in the browser. For a reliable statement about cookies you need your browser’s developer tools or a check with a real browser.

Watched continuously

The check is a snapshot. In DomainWarn it runs daily for every customer domain: if a new service appears – because someone embedded a video or installed a plugin – it shows up in the timeline, and Google Fonts or active tracking open an incident with an alert.

Frequently asked questions

Does this replace legal advice?
No. The check shows technically which third parties the home page loads. Whether consent is required in a specific case depends on the service, the configuration and the legal basis – that is for a lawyer or data protection officer to judge.
Only the home page?
Yes, the home page is checked. It usually embeds the same fonts, scripts and consent tooling as the rest of the site. Individual subpages with embedded maps or videos may load further services.
My consent manager blocks it, why is the service still listed?
Blocked services are listed as information with a “blocked” note – that is not a finding but confirmation that the blocking is visible in the HTML.
What about services the check does not know?
Unknown third-party hosts are collected and listed without judgement, so you can see niche services and classify them yourself.
Monitor continuously
Monitor the websites of all client domains continuously

Website monitoring for agencies: DomainWarn checks availability, status code, response time, redirects, IPv6, headers and content of all client websites.

More about monitoring

More tools

Free tool

Domain Check

Check website, email, DNS and domain in one run: 13 checks, a score from 0 to 100 per area and overall, with recommendations. Free, no sign-up required.

Open tool →
Free tool

Email header analyzer

Paste email headers and read them in plain words: did SPF, DKIM and DMARC pass, does the sender domain align, which servers relayed it, how long it took?

Open tool →
Free tool

Email Check

Check SPF, DKIM, DMARC and MX of a domain in one run, free and without sign-up. Shows whether your mail meets the Google and Yahoo sender requirements.

Open tool →
Free tool

SPF Checker

Free SPF record check and lookup: syntax, includes, the 10 DNS lookup limit and the closing qualifier. Shows whether your domain blocks forged senders.

Open tool →
Free tool

DMARC Checker

Free DMARC record check: policy (none, quarantine, reject), pct, reporting addresses and syntax errors. With recommendations for moving to p=reject.

Open tool →
Free tool

DNS Checker

Free DNS lookup straight from the authoritative name server: A, AAAA, CNAME, MX, TXT, NS and CAA records at a glance. No sign-up, every record explained.

Open tool →
Free tool

MX Checker

Free MX lookup: which mail servers receive for a domain, do they resolve, is the priority right? Detects missing and unreachable mail servers.

Open tool →
Free tool

SSL Checker

Free SSL certificate check: expiry date, issuer, chain, host name and TLS version, mail servers too. Detects expired, self-signed and mismatched certificates.

Open tool →
Free tool

HTTP Header Checker

Free HTTP header check: HSTS, Content-Security-Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy and Permissions-Policy, with fixes.

Open tool →
Free tool

Is the website down?

Website not loading? Check for free whether a site is down for everyone or just for you: response, status code, load time, redirects and IP addresses.

Open tool →
Free tool

DNS Propagation Checker

Check DNS propagation for free: which resolvers worldwide (Google, Cloudflare, Quad9 …) already return the new A, MX or TXT record, which still the old one?

Open tool →
Free tool

Redirect Checker

Free 301 redirect check: every hop with status code and response time, from http to https, from www to non-www. Detects redirect chains, loops and 302s.

Open tool →
Free tool

DKIM Checker

Free DKIM record check and lookup: selector, key type, key length, syntax and revoked keys. Leave the selector empty to try common selectors automatically.

Open tool →
Free tool

DNSSEC Checker

Free DNSSEC test: DS record, resolver validation and broken signature chains. Shows whether validating resolvers like Google and Cloudflare still reach you.

Open tool →
Free tool

MTA-STS Checker

Free MTA-STS check: DNS record, policy file, mode, max_age and whether your MX servers are covered. Shows whether inbound mail enforces TLS.

Open tool →
Free tool

TLS-RPT Checker

Free TLS-RPT record check: syntax, reporting addresses (rua) and common errors such as a missing record. Shows whether you get reports on TLS failures.

Open tool →
Free tool

BIMI Checker

Free BIMI record check: syntax, logo URL, SVG Tiny PS, VMC certificate and the DMARC prerequisite. Shows why your logo does not appear in Gmail.

Open tool →
Free tool

Blacklist Check

Free IP and domain blacklist check: mail server IPs, website IP and domain against Spamhaus, Spamcop, Barracuda, PSBL and SURBL. With delisting links.

Open tool →
Free tool

Domain Checker

Free domain check: WHOIS data via RDAP straight from the registry, expiry date, registrar, EPP status, transfer lock and name servers. Warns before expiry.

Open tool →