Does your “Reject all” button actually work?

We visit your site as a new visitor, click the reject option on your own banner, reload, and record every tracker and cookie that still loads.

No signup · nothing installed · results in about a minute

  • Trackers before a choice
  • Trackers after “Reject”
  • Cookies set anyway
  • Reject on the first layer
  • Equal buttons

Why the reject button is where fines start

A banner can look perfect and still do nothing when people say no. In September 2025, France’s CNIL fined SHEIN €150 million: ad cookies were set before any choice, and clicking “Refuse all” didn’t stop new cookies being set or old ones being read. In November 2025, the publisher of vanityfair.fr was fined €750,000, again partly because “Refuse all” didn’t stop tracking.

It isn’t only a European problem. In 2025 the California Attorney General settled with Healthline Media for $1.55 million, in part because its consent banner didn’t switch off tracking cookies.

See every case in the fines tracker.

What the test does

  1. A brand-new visitor

    A real browser with no cookies opens your homepage and records every request and cookie before anyone touches the banner.

  2. We find your banner

    Including banners inside frames and shadow DOM. We recognise the common consent tools, and AI reads unusual button wording in any language.

  3. We click your own reject button

    “Reject all”, “Only necessary”, “Refuse” or whatever your banner calls it, and reload the page.

  4. We record what still fires

    Every analytics, advertising and session-replay request and cookie after the refusal is listed with its timing and the vendor behind it.

Why reject buttons fail

  • A tracking snippet hard-coded in the theme, or added by an app or plugin, bypasses the consent tool.
  • Tags in Google Tag Manager fire on “All Pages” instead of a consent trigger.
  • The consent tool is set to “notice only”, or to a different region, so it never blocks anything.
  • The same pixel is installed twice, and only one copy waits for consent.
  • Cookies set before the refusal are never cleared and keep being read.

Test it by hand

  1. Open your site in a private window.
  2. Click the banner’s “Reject all”.
  3. Open DevTools → Network and reload the page.
  4. Search the requests for google-analytics, facebook, tiktok, doubleclick, clarity and hotjar, and check Application → Cookies. Nothing non-essential should load or be set.

Questions people ask

Which banners does the test work with?

Any banner a visitor can click. We recognise OneTrust, Cookiebot, CookieYes, Didomi, Usercentrics, Complianz, iubenda, Borlabs and more, and custom banners work too.

What if my banner only shows in some countries?

Our browser uses British English on Central European time. If your consent tool decides by visitor location, the report reminds you to confirm the banner appears for EU and UK visitors.

Does the test change anything on my site?

No. We only visit your public pages like any visitor would. Nothing is installed, and the click only affects our own browser.

Is it really free?

Yes: the free scan checks your homepage, with no signup. A free account keeps the full report; Pro scans up to 8 key pages per scan and re-checks daily.

Sources

  1. CNIL: SHEIN fined €150 million (Sept 2025)
  2. CNIL: vanityfair.fr publisher fined €750,000 (Nov 2025)
  3. California Attorney General: Healthline Media settlement (July 2025)
  4. CNIL: formal notices over dark-pattern cookie banners (Dec 2024)

Find out what your “Reject” really does.

Find out in about a minute. Free, no signup.

No signup · nothing installed · results in about a minute