Skip to main content
SlapMyWeb
Analytics

Third-Party Cookies

Cookies set by a domain other than the one being visited, now blocked by most browsers.

A third-party cookie is one set by a domain other than the site being visited — typically an ad network or analytics vendor loaded in an iframe or script. Safari and Firefox have blocked them for years and Chrome has restricted them, which is why cross-site tracking, view-through attribution and some embedded tools no longer work as they did.

Definition

A first-party cookie is set by the site in the address bar; a third-party cookie is set by another domain whose resources that page loads. The second kind is what allowed one advertiser to recognise the same person across unrelated sites.

Browser policy has moved decisively against them. The consequences for measurement are real: attribution windows shorten, cross-domain journeys break, and some vendor scripts silently stop identifying returning visitors.

Why It Matters

Analytics that assumed third-party cookies now under-report. Anything that depended on recognising a user across domains needs a first-party or server-side replacement rather than a patch.

Example

An ad pixel on publisher.com setting a cookie for adnetwork.com is third-party. The same site's own session cookie for publisher.com is first-party and unaffected.

What breaks, and what to do about it

Three things stop working as browsers restrict third-party cookies. Cross-domain user recognition — the same person on your marketing site and your app on a different domain — becomes two people. View-through attribution largely disappears. And any embedded tool that relied on recognising a returning visitor from another origin loses that ability.

The replacements are first-party and server-side. A first-party cookie set by your own domain is unaffected. Server-side tagging moves the identification off the browser entirely. Consent-based first-party identifiers work where you have a logged-in relationship.

What does not work is patching around it — the alternatives that attempted to recreate cross-site recognition through fingerprinting are explicitly targeted by the same browser policies, and by privacy regulation that is moving faster than either.

How SlapMyWeb checks this

The audit inventories the cookies a page sets and the third-party origins it loads resources from, and reports cookies missing Secure, HttpOnly or SameSite. The matching fix guide is how to secure cookies. What it does not do is judge your analytics setup — that is a measurement decision rather than a site defect.

Know the term.
Check your own site.

A free audit tells you whether this is currently costing you score points — and exactly what to change.

Run a free audit
Free foreverNo signupResults in 30s