Ensuring Website Access
Scanner IP addresses, Shopify crawler signature, firewalls, Basic Authentication and other checks so Monitoring can scan your website
Last updated About 3 hours ago
Using Shopify, or can't allowlist IP addresses? Jump to Web Bot Auth, for example on Shopify.
Looking for our IP addresses? Jump to Scanner IP addresses.
Consent Studio Monitoring opens your pages in a real browser to detect tracking technologies and check your implementation. Use the checks below to make sure our scanner can reach your website and read your pages. If our scanner is blocked, you get the critical recommendation Site access blocked.
Scanner IP addresses
Monitoring visits your website from the IP addresses below. You need them to:
allow our scanner through your firewall, WAF, security plugin or bot protection, so we can scan your website in the first place;
filter our visits out of your analytics, so our scans are not counted as real page views.
51.15.69.16751.15.75.157
Last update: October 1st, 2025. We do our best to keep this list as short as possible.
Can't allowlist IP addresses, for example on Shopify? If your platform or bot protection supports Web Bot Auth, use a crawler signature instead: see Web Bot Auth.
Cloudflare
Log in to Cloudflare and select the domain you use with Consent Studio.
Add a rule that allows requests from each of our scanner IP addresses, so they are not blocked or challenged by Cloudflare's firewall or bot protection.
Save the rule.
Get a new scan, or wait for the next weekly one (see the Scanning FAQ). Once a scan succeeds, the Site access blocked recommendation closes by itself.
Other firewalls and bot protection
The same approach works for any other protection in front of your website, such as a WAF, a security plugin, a bot protection app or your hosting provider's firewall: add our scanner IP addresses to its allowlist.
Using more than one layer, for example Cloudflare and a security plugin? Allowlist our IP addresses in each of them.
Don't manage the firewall yourself? Ask your hosting provider or developer to allow our scanner IP addresses.
No firewall of your own, but still blocked? Some hosting platforms, such as Webflow, block automated visitors on their side. See Site access blocked.
Still blocked after allowlisting? Contact us with your domain and we'll dig deeper on our side.
Web Bot Auth, for example on Shopify
Some platforms and bot protection services block automated visitors and don't let you allowlist IP addresses. If they support Web Bot Auth, you create a crawler signature there and add it on the Access tab of Domain Settings. Monitoring then sends the signature with every request, so it gets past the bot protection. Shopify is the best-known example: it doesn't let you allowlist IP addresses, and its "Crawler access" feature creates these signatures. For step-by-step instructions, see Web Bot Auth.
Password-protected sites (Basic Authentication)
Is your website protected with a username and password, for example a staging or test site? Then Monitoring cannot see your pages until you add the username and password under Basic Authentication.
Basic Authentication only works with HTTP Basic Authentication: the username/password prompt your browser shows before any page loads. Login forms on a web page, such as a WordPress login page, are not supported. Shopify stores with password protection (the storefront password page) are not supported either.
In Consent Studio, open Domain Settings via the gear/cog icon in the top bar.
Open the Access tab.
Under Basic Authentication, enter the username and password of your website and save.
Get a new scan, or wait for the next weekly one (see the Scanning FAQ). Once a scan succeeds, the Site access blocked recommendation closes by itself.
Pages timing out
If a page loads too slowly, our scanner cannot process it in time and the page times out. Your consent banner still works fine for your visitors; only the scan of that page is affected.
Our scanner bypasses caches. We use cache busting when we scan, so a page that loads quickly from cache for you can still be slow for our scanner.
Check mobile speed too. A page can load fast enough on desktop but too slowly on mobile.
A few timeouts are not always a problem. If most pages scan fine, Monitoring still finds the tracking technologies on your site.
Once you have improved your page speed, get a new scan (see the Scanning FAQ).
SSL and certificate problems
Make sure your domain has a valid SSL certificate. If it doesn't, our scanner cannot load your pages.
www, non-www and redirects
Make sure the non-www variant of your domain is reachable, as well as the www variant if you use it.
Choose the right pages to scan
Monitoring checks your home page plus the pages on your Pages to Scan list, so add the pages that load something different, such as a video or a form. See Choose which pages Monitoring scans. On Professional and up, a sample of your sitemap is added too: see Sitemap Based Scanning.
FAQ
Does Basic Authentication work with a login form, such as a WordPress login page?
No. Only HTTP Basic Authentication (the browser's own username/password prompt) is supported. Monitoring cannot fill in login forms on a web page, such as a WordPress login page.
My Shopify store is password-protected. Does Basic Authentication work?
No. A password-protected Shopify store can't be scanned until the store password is removed. To let Monitoring past Shopify's bot protection after that, use a crawler signature (Web Bot Auth).
My staging site is added as a domain alias. Is it scanned?
No, only your primary domain is scanned. See Domain Aliases.
My staging site only allows certain IP addresses. What do I do?
Allow our scanner IP addresses.
Where can I find more answers about scanning?
See the Scanning FAQ, or contact us with your domain.
Was this helpful?
More in Scanning & Access
Sitemap Based ScanningWeb Bot AuthStill need help? Ask the team