How to block or limit trackers
Published September 27, 2026
There's no single setting that stops all tracking, because tracking isn't one technique — it's cookies, browser fingerprinting, server-side matching, and more, each requiring a different countermeasure. Here's what your realistic options actually do, without pretending any one of them is complete.
Browser settings
Every major browser now ships some tracking protection turned on by default, but they differ in how far they go:
- Safari blocks third-party cookies entirely by default and applies Intelligent Tracking Prevention (ITP) to first-party ones too, including the 7-day cap on script-set cookies covered in how cookie lifetimes work.
- Firefox ships Enhanced Tracking Protection (Standard or Strict, in Settings → Privacy & Security), which blocks known third-party tracking cookies and isolates the rest so different sites can't correlate them, using a maintained list of tracking domains.
- Chrome offers a "Block third-party cookies" setting (Settings → Privacy and security → Third-party cookies) and, separately, a "Do Not Track" request that most sites simply ignore, since it was never a binding standard.
What this stops: classic third-party cookie tracking — the kind where an ad network's cookie follows you across every site that embeds it.
What it doesn't stop: first-party analytics identifiers like _ga (blocking third-party cookies has no effect on a cookie the site itself sets under its own domain — see first-party vs third-party cookies), browser fingerprinting, or anything a site does on its own servers after it collects data by other means.
Content blockers
Browser extensions and built-in blockers (uBlock Origin and similar tools, Brave's Shields, Safari and Firefox's content-blocking APIs) work from curated filter lists that block requests to known tracking and advertising domains outright — the request never leaves your browser, rather than being allowed through and then having its cookie ignored.
What this stops: most third-party advertising, analytics and social widget requests that match the list, including many that survive plain browser cookie settings.
What it doesn't stop: anything not on the list, including newly registered tracking domains and — notably — CNAME-cloaked or server-side-tagged trackers that are deliberately set up to look like first-party site infrastructure rather than a recognizable third-party domain. It's an ongoing back-and-forth: block lists get updated as new tracking domains are identified, and some sites and ad-tech vendors actively restructure their setup to dodge them.
The trade-off: blocking requests outright can break things that depend on them — comment widgets, embedded videos, some login flows, and any "if this script fails, show an error" page that a site built without expecting it to be blocked. Some sites also detect ad blockers and ask you to disable them or pay for access.
Global Privacy Control (GPC)
Global Privacy Control is a signal your browser or an extension sends automatically with every page request — either as an HTTP header (Sec-GPC: 1) or a small piece of information the page's JavaScript can read — that communicates "this visitor does not want their data sold or shared." Firefox, Brave and several other browsers support it natively; Chrome and Safari currently require an extension.
What this stops: in jurisdictions that recognize it as a valid legal opt-out — California's CCPA/CPRA is the clearest example, and a handful of other US states have followed — a site is legally required to honor GPC the same way it would honor an opt-out request made by hand, without you visiting a settings page on every site. It's a real legal mechanism where it applies, not just a polite request.
What it doesn't stop: GPC only requests an opt-out from selling or sharing data; it doesn't block a single tracking request by itself the way a content blocker does, and it doesn't stop anything from loading before you've had a chance to send it. Its legal weight also varies a lot by jurisdiction — in the EU, whether GPC counts as a valid, standing objection to processing under GDPR Article 21, or a substitute for the cookie consent covered in what counts as valid consent, is genuinely unsettled and argued differently by different regulators; treat it as a US-centric tool for now, not an EU cookie-consent mechanism.
Clearing cookies
Deleting cookies (browser settings, or a "clear on exit" extension) removes identifiers a site has already set, resetting whatever profile was tied to that browser.
What this stops: it breaks the continuity of any identifier stored purely in cookies — the next visit looks, cookie-wise, like a first-time one.
What it doesn't stop: it doesn't prevent the same tracking from happening again on your next visit (the cookie just gets re-created), and it does nothing about tracking methods that don't rely on cookies at all, like browser fingerprinting or identifiers derived from your IP address and device characteristics. It also logs you out of everything and clears saved preferences, which is the main reason people don't do it constantly.
Putting it together
None of these four is a complete answer, and none is mutually exclusive with the others — a content blocker plus tightened browser cookie settings covers more ground than either alone, and clearing cookies periodically limits how long any identifier that gets through actually persists. What none of them does is verify what a specific site is doing before you take any of these steps, which is what a scan — your own, using browser DevTools, or this site's monthly one — is for.