---------------------------
Title: What Cookies Does My Website Use? Three Ways to Find Out (and Why Only One Is Reliable)
URL: https://www.cookiebot.com/en/what-cookies-does-my-website-use/
---------------------------

# What Cookies Does My Website Use? Three Ways to Find Out (and Why Only One Is Reliable)

A comparison of three methods for auditing a website's cookies (browser DevTools, automated scanning, and manual audit) and why only an automated scan reliably matches what a regulator would find.

## Key Takeaways

- There are three practical ways to find out what cookies your site uses: browser DevTools, an automated cookie scanner, or a manual audit.
- Browser DevTools can show cookies as they fire, but reaching every cookie on every page under every user state is impractical for a real site. And even then, nested third-party cookies are hard to attribute to the vendor that set them.
- An automated scanner is the only method that reliably produces the same list a regulator would find, because it crawls your whole site and simulates consent automatically.
- Tracking cookies aren't illegal, they're regulated. The EU's ePrivacy Directive and the [General Data Protection Regulation (GDPR)](/en/gdpr/) require prior consent for non-essential cookies; the [California Consumer Privacy Act (CCPA)](/en/what-is-ccpa/) requires a clear opt-out.
- Every cookie you fail to declare because you didn't find it is a potential GDPR breach, which is why "run the scan" is the practical answer for most sites.

If you're trying to figure out what cookies your website uses, there are three practical ways to do it. Check them in your browser's developer tools, run an automated scanner, or audit them manually against your tag manager and cookie banner. All three will show you something. Only one will show you everything. And if you rely on the browser check alone, you'll likely miss cookies that only a full scan would catch.

This guide walks through all three methods, then explains why the browser check misses so much. If you already know you need a full picture and just want the fastest way to get it, run a free scan with [the cookie checker from Cookiebot by Usercentrics](/en/cookie-checker/), otherwise, keep reading.

## Method 1: Check Your Site’s Cookies in the Browser (DevTools)

The fastest way to see cookies on your site in Chrome:

1. Open your site in Chrome.
2. Right-click anywhere on the page and choose **Inspect**.
3. In the DevTools panel that opens, click the **Application** tab (you may need to click the » arrow to find it).
4. In the left sidebar, expand **Cookies** and click your domain.

You'll see a list of every cookie currently set for your domain in this browser session: name, value, expiry, whether it's marked HttpOnly or Secure. Firefox and Safari have equivalent panels (Storage Inspector and Web Inspector respectively) that show the same data.

The list updates in real time. If you accept your cookie banner, more cookies will appear as consent-gated scripts fire. Navigate to a different page and any cookies that page sets will be added too. So with enough clicking and enough patience, a DevTools check can catch a lot — the question is whether "enough" is realistic for a site with dozens of pages and dozens of vendor scripts.

## Method 2: Run an Automated Cookie Scanner

An automated scanner crawls your site the way a first-time visitor would, then repeats the crawl after simulating consent to trigger the cookies that only fire after acceptance. It catalogs every cookie it finds, categorizes them (necessary, statistics, marketing, and preferences), and produces a report you can act on.

This is the only method that consistently produces the same list a regulator would find. [The free cookie checker from Cookiebot by Usercentrics](https://www.cookiebot.com/en/cookie-checker/) scans up to five subpages of any site and emails you the full report; the paid tier scans your entire domain on a monthly cadence, catching new cookies that arrive when someone installs a plugin or adds a tag.

## Method 3: Manual Audit

A manual audit is useful when you want to verify what a scanner reports, or when you're specifically trying to identify who added something. Walk through:

- **Your cookie banner declaration.** What is the banner currently telling visitors you set? This is what you're accountable for and where discrepancies with reality usually show up first.
- **Your cookie policy.** Cross-reference every cookie declared in the policy against what's actually firing. Missing entries are privacy compliance gaps.
- **Your tag manager containers.** Open Google Tag Manager (or your equivalent) and list every tag firing on your site. Note which set cookies directly.
- **Embedded third-party scripts.** Chat widgets, video embeds, ad pixels, and social-share buttons all load [third-party trackers](/en/tracking-cookies/) that can set their own cookies without appearing in your tag manager.

A manual audit catches misconfigurations a scanner might not flag, but it takes hours and misses dynamically loaded trackers that only appear under specific conditions.

## Why the Browser Method Under-Reports in Practice

DevTools can show you a lot if you use it thoroughly. The problem is that "thoroughly" means reproducing every state a real visitor might reach, and doing that manually is impractical. Here's what a naive check misses, and what even a diligent check still misses.

### Cookies You Haven't Triggered Yet

DevTools shows what's set in the browsing session in front of you. If you haven't accepted the banner, marketing and statistics cookies are (correctly) blocked and won't appear. If you haven't visited the checkout page, cookies that only fire there won't appear. If you haven't scrolled to the embedded video, its cookies won't appear. A single homepage check before consent, the way most people run this, captures almost none of what a regulator would find.

### Cookies That Only Appear Under Specific Behavior or Timing

Some scripts set cookies only after a return visit, a specific action (add-to-cart, form submission, login), or after a delay. Reproducing every one of these states manually on a real site takes hours, and it's easy to miss one.

### Nested Third-Party Cookies Whose Origin You Can't Tell

A single Google Tag Manager container can load a dozen vendor scripts, such as Google Analytics, Meta Pixel, Hotjar, an ad network, and a chat widget. Each of those vendors can set its own cookies, and each vendor's script can in turn load other vendor scripts that set cookies too. DevTools will list those cookies once they fire, but it won't tell you which vendor chain set which cookie or which of them you're accountable for declaring. Untangling that from the browser alone is genuinely difficult.

### Check Every Page Separately

Even if you're methodical, you have to repeat the check on every page of your site, homepage, blog, product pages, checkout, contact form, and logged-in areas. Because each one loads a different set of tags. On a site with 50 pages that's 50 manual checks.

An automated scanner does all of this at once: it crawls every page it can find, simulates consent, catalogs each cookie against the vendor that set it, and produces a report you can act on. The difference between the two methods comes down to practicality: DevTools can see cookies, but assembling a complete picture with it takes more time than most sites can spare. Every cookie you fail to declare because you didn't find it is a potential GDPR breach.

## Which Method Should I Use?

If you just want a rough sense of what's on your homepage: DevTools is fine. If you need to know what regulators or an independent scan would find on your site: run an automated scan. If you're auditing a specific vendor or investigating a misconfiguration: do the manual audit alongside the scan. Realistically, if you're a business owner responsible for your site's privacy compliance, you need the scan, everything else is triangulation.

For teams weighing which scanner or full consent management platform (CMP) to use, our [comparison of the best consent management platforms](/en/best-consent-management-platforms/) covers the shortlist worth considering.

## So What's Actually Running on Your Site?

Of the three methods, only one holds up under real scrutiny. An automated scan is the one built to match what a regulator would find. DevTools works, but only if you manually check every page under every visitor state, impractical for most sites. Even then, nested third-party cookies are hard to trace to their source from the browser alone. A manual audit takes longer still and can miss cookies that load dynamically. If your site's privacy compliance depends on knowing what's actually running, the scan is the fastest way to find out.

## Automate Your Cookie Compliance

Automatically find, categorize, and manage every cookie and keep your privacy compliance program current as your site changes with Cookiebot by Usercentrics

[Start Free](https://admin.cookiebot.com/signup?utm_source=blog&utm_medium=content-distribution&utm_campaign=blog-organic)

**Legal Disclaimer:** Usercentrics does not provide legal advice, and information is provided for educational purposes only. We always recommend engaging qualified legal counsel or privacy specialists regarding data privacy and protection issues and operations.

---

## Footer

### Products
- [Cookiebot™ Consent Solution](https://www.cookiebot.com/en/cookie-consent-solution/)
- [Audience Survey](https://www.cookiebot.com/en/audience-survey-add-on/)
- [Usercentrics for Wix](https://www.cookiebot.com/en/cookiebot-for-wix-by-usercentrics-app/)
- [Usercentrics Cookiebot plugin for WordPress](https://www.cookiebot.com/en/new-wp-cookie-plugin/)
- [Cookiebot CMP for Shopify](https://www.cookiebot.com/en/cookiebot-cmp-for-shopify/)
- [Cookie checker](https://www.cookiebot.com/en/cookie-checker/)
- [Usercentrics products](https://usercentrics.com/)
- [Pricing](https://www.cookiebot.com/en/pricing/)

### Regulations
- [DMA (EU)](https://www.cookiebot.com/en/digital-markets-act-dma/)
- [GDPR (EU)](https://www.cookiebot.com/en/gdpr/)
- [CCPA (California)](https://www.cookiebot.com/en/what-is-ccpa/)
- [VCDPA (Virginia)](https://www.cookiebot.com/en/virginia-vcdpa/)
- [LGPD (Brazil)](https://www.cookiebot.com/en/lgpd/)
- [TCF v2.4 (IAB)](https://www.cookiebot.com/en/tcf/)
- [Google Consent Mode (EU)](https://www.cookiebot.com/en/cookiebot-cmp-google-consent-mode/)
- [Microsoft UET Consent Mode](https://www.cookiebot.com/en/microsoft-consent-mode-cmp/)
- [View all regulations](https://www.cookiebot.com/en/regulations-and-frameworks/)

### Partners
- [Become an affiliate](https://www.cookiebot.com/en/affiliates/)
- [Affiliate Login](https://app.impact.com/login.user)
- [Become a partner](https://www.cookiebot.com/en/resellers/)
- [Find a partner](https://www.cookiebot.com/en/cookiebot-reseller/)

### Resources
- [Blog](https://www.cookiebot.com/en/blog/)
- [Customer stories](https://www.cookiebot.com/en/customer-stories/)
- [Customer directory](https://www.cookiebot.com/en/cookiebot-customer-directory/)
- [Digital Markets Act Hub](https://www.cookiebot.com/en/digital-markets-act-dma-resources/)
- [Google Consent Mode Hub](https://www.cookiebot.com/en/google-consent-mode-resources/)
- [Google Consent Mode V2 certification](https://courses.usercentrics.com/course/google-consent-mode-v2)
- [Google Consent Audit Fixes](https://www.cookiebot.com/en/google-consent-audit-fixes/)
- [Cookie Banner Cost Calculator](https://www.cookiebot.com/en/cookie-banner-pricing-calculator/)

### Company
- [About us](https://www.cookiebot.com/en/about/)
- [Careers](https://usercentrics.com/career/)
- [Support](https://support.cookiebot.com/hc/en-us/)
- [Developer documentation](https://www.cookiebot.com/en/developer/)

©2026 Cookiebot. All rights reserved. Cookiebot is a trademark of     Usercentrics     A/S. Usercentrics A/S is registered in Denmark. Company reg. no.: 34624607. Do Not Sell or Share My Personal InformationData Subject RequestsManage Your Preferences

[Privacy Policy](https://www.cookiebot.com/en/privacy-policy/) · [Terms of Service](/en/terms-of-service/) · [Cookie Declaration](https://www.cookiebot.com/en/cookie-declaration/) · [Data Processing Agreement](https://www.cookiebot.com/en/data-processing-agreement/) · [Legal Notice](https://www.cookiebot.com/en/legal-notice/) · [Accessibility Statement](https://www.cookiebot.com/en/accessibility-statement-wcag-compliance/)