Third-party request map

Opening one page usually means talking to a dozen companies you never heard of. This map names each one, says what kind of service it is, and pins its servers on a world map.

Or try bbc.com, nytimes.com

A page is assembled from many servers

The address in the browser bar names one site, but the HTML that comes back is really a list of errands. Fetch this font from Google, this script from a tag manager, this video player from YouTube. The browser does as it’s told and opens a connection to each of those hosts. Any host that doesn’t belong to the site you’re visiting is a third party.

None of these connections is anonymous. Each one carries the visitor’s IP address, the browser and system in the User-Agent header, and normally a Referer header naming the site or the exact page being read. If the third party has stored a cookie in that browser before, on any site, the cookie goes along too. So a company present on many sites can recognize one person moving between them. Often the site owner never chose any of this, and a theme or a plugin added the request.

How the map is drawn

Our server downloads the page and reads its source. It collects the hosts named in scripts, stylesheets, images and srcset lists, media, iframes, preconnect and preload hints, form targets, CSS url() values and tracking pixels inside <noscript>. When the page loads Google Tag Manager, we fetch the container file as well (two containers at most) and search it for services it can inject.

Each host is compared with a list of about 120 known services, which gives a name, an owner, the country of the owner’s headquarters and a category. Hosts that match nothing are grouped by domain and shown as unidentified. An address that’s merely written inside an inline script is kept only when it belongs to a known service, because scripts mention plenty of addresses they never call.

Up to 40 hosts are then located. A DNS query returns an IP address, and the Team Cymru IP-to-ASN service returns the network that announces that address and the country where the block is registered. The table is sorted from the most intrusive category to the least: advertising, analytics, social media, marketing, chat, video, maps, forms, payment, fonts, bot protection, consent tools, libraries, hosting. The “Tracking” counter adds up the first four.

Three meanings of “where”

Where the IP block is registered
This is what the map shows. It’s an administrative fact recorded by the regional internet registries.
Where the machine that answers stands
Large networks announce the same address from data centers on every continent and route each visitor to the nearest one. A block registered in the United States may be answered from Frankfurt for a visitor in Germany, and the data may get copied somewhere else afterwards.
Where the company is based
Shown as “HQ” in the table. It decides which courts and authorities can demand data from the company, wherever its machines are.

Laws on international transfers mostly look at the third meaning and at the contract in place. Under Chapter V of the GDPR, personal data may leave the European Economic Area only toward a country covered by an adequacy decision, or with safeguards such as standard contractual clauses.

Shortening the list

  • Remove what nobody uses. Pixels from finished campaigns and widgets from uninstalled plugins go on reporting for years.
  • Serve static files yourself. Fonts, icon sets and script libraries can be copied to your own domain. With HTTP/2 that’s usually faster than a public CDN, since browsers no longer share cached files between sites.
  • Load embeds on demand. Show an image in place of a video or a map and load the real thing on click. The click-to-load embed tool writes that code.
  • Say less to those that remain. Referrer-Policy: strict-origin-when-cross-origin sends third parties your domain instead of the full page address.
  • Keep the list from growing back. A Content-Security-Policy header works as an allowlist. A host that isn’t on it can’t be called, whatever a plugin adds.

Scripts aren’t run. A service that another script loads later, or that only appears after the visitor accepts cookies, can be missing, and a host named in the source isn’t always contacted for every visitor. Services marked “form submission” receive data only when someone sends the form. To see which trackers start before consent, run the cookie scan.

Questions people ask

What is a third-party request?

A request the browser makes, while loading a page, to a domain other than the one being visited. A font from fonts.googleapis.com on your site is one. An image from your own subdomain isn’t.

Is an IP address personal data?

Under the GDPR, generally yes. The EU Court of Justice held in the Breyer case (2016) that even a dynamic IP address is personal data when the party holding it has legal means to identify the person. Several US state laws list IP addresses among personal information too.

Why is an American company shown in another country?

The map shows where each IP block is registered, and global companies hold blocks registered in many countries. The company’s home country is a separate fact, and you’ll find it on the “HQ” line in the table.

Is loading scripts from a CDN a privacy problem?

The CDN operator sees the IP address of every visitor and the site they came from. You also depend on it for security, since whoever controls that file controls your page. Hosting the file yourself avoids both. If you keep the CDN, add an integrity attribute so that a modified file gets rejected.

How do I see third-party requests in my own browser?

Open the developer tools, choose the Network tab and reload the page. The Domain column shows every host contacted. Chrome and Edge have a “3rd-party requests” filter. That view includes what scripts load, which our map can’t see.

Why is a service I use missing from the map?

It’s probably added by JavaScript after the page loads, or held back by your consent banner until the visitor accepts. Only hosts written in the HTML source or in a Tag Manager container appear here.