Skip to main content
Blog
Blog security

What Is That Tracker? A Field Guide to the Domains in Your Network Tab

You open DevTools and see requests to doubleclick.net, adnxs.com, clarity.ms, scorecardresearch.com — domains you never added. This guide explains what the most common tracker domains actually are, who operates them, what data they touch, and when an unknown domain in your network tab is a real problem.

Aug 18, 2026 8 min read
What Is That Tracker? A Field Guide to the Domains in Your Network Tab
Table of Contents

Open DevTools on almost any commercial website and the network tab fills with domains nobody on your team remembers adding: doubleclick.net, adnxs.com, clarity.ms, scorecardresearch.com, bidswitch.net. Some arrived through your tag manager. Some were loaded by scripts that were loaded by scripts. All of them execute in your users' sessions, under your name.

This is a field guide to the tracker domains people look up most, what each one actually is, who operates it, what data it touches, and when an unfamiliar domain is a real problem rather than adtech background noise.

Why unknown domains appear on your site

Scripts load scripts. You add a tag manager, an ad partner, or an analytics tool, and it pulls in its own dependencies, which pull in theirs. A single programmatic ad slot can call out to a dozen exchanges during header bidding. None of this appears in your source code — the chain exists only in the browser, at runtime. That is why the network tab is where you discover it, and why a repository audit will never explain it.

The domains below are grouped by what they do. For each: what it is, who runs it, and what it means to see it.

What is doubleclick.net?

doubleclick.net is Google's advertising infrastructure — the legacy domain of DoubleClick, which Google acquired in 2008 and folded into Google Marketing Platform and Google Ad Manager. It serves display ads, tracks impressions and clicks, and sets advertising cookies used for frequency capping and conversion measurement. If your site runs Google ads, or your visitors were shown one elsewhere and clicked through, doubleclick.net requests are expected. It is one of the most common third-party domains on the web.

What is googlesyndication.com?

googlesyndication.com serves the static assets of Google's ad network — the actual creative files, scripts, and safeframe containers behind AdSense and Ad Manager placements. Seeing it means Google ads render on the page. It works together with doubleclick.net (measurement) and 2mdn.net (rich media assets).

What is 2mdn.net?

2mdn.net is Google's CDN for rich media ad creatives — video, HTML5, and interactive ad assets served for DoubleClick/Google Marketing Platform campaigns. It appears whenever a rich media ad renders on a page. It is a content-delivery domain rather than a tracking endpoint, but it arrives as part of the same ad-serving chain.

What is clarity.ms?

clarity.ms belongs to Microsoft Clarity, a free behavioral analytics tool that records session replays, heatmaps, and interaction metrics. If it appears on your site, someone installed Clarity or enabled it through a plugin. Session-replay tools deserve attention in any privacy review: they capture user interactions in detail, and misconfigured replay tooling has repeatedly been shown to capture form input it should have masked.

What is hotjar.com?

hotjar.com (and its asset domain hotjar.io) is Hotjar, one of the most widely deployed heatmap and session-recording tools. Like Clarity, it is legitimate and common — and like Clarity, it is a script that observes user behavior in detail, so it belongs on your consent-managed list and inside whatever masking policy your privacy team maintains.

What is adnxs.com?

adnxs.com is the ad-serving domain of Xandr, the exchange formerly known as AppNexus, acquired by Microsoft in 2022. It is one of the largest programmatic advertising platforms, and its pixels and scripts appear on any page participating in Xandr's marketplace — usually via header bidding rather than a direct integration you chose.

What is rubiconproject.com?

rubiconproject.com belongs to Magnite, the sell-side advertising platform formed when Rubicon Project merged with Telaria in 2020. The legacy domain still carries its ad-serving and header-bidding traffic. Publishers integrate Magnite to auction their ad inventory; its requests on your site mean your pages (or an embedded partner's) participate in those auctions.

What is pubmatic.com?

pubmatic.com is PubMatic, a major sell-side platform (SSP) that runs programmatic auctions for publisher ad inventory. Like Magnite and OpenX, it typically arrives through header-bidding wrappers — one ad integration fans out into requests to every exchange in the wrapper's configuration.

What is openx.net?

openx.net is OpenX, another of the large independent ad exchanges. Its presence means ad inventory on the page is being offered through OpenX's marketplace. Same pattern as PubMatic and Magnite: legitimate, widespread, and almost never something a developer added by hand.

What is casalemedia.com?

casalemedia.com is the legacy domain of Index Exchange, an ad exchange that grew out of Casale Media. The old hostname still carries its bidding and ad-serving traffic, which is why a company name you cannot find matches a domain you see constantly — the domain outlived the brand.

What is 3lift.com?

3lift.com is TripleLift, a programmatic platform specialising in native advertising — ads styled to match the surrounding content. Its requests appear when native ad units on the page are filled through TripleLift's exchange.

What is sharethrough.com?

sharethrough.com is Sharethrough, another native advertising exchange (merged with District M in 2021). Like TripleLift, it appears wherever native ad slots are auctioned programmatically.

What is bidswitch.net?

bidswitch.net is BidSwitch, infrastructure operated by IPONWEB (acquired by Criteo in 2022) that routes bid traffic between demand-side and sell-side platforms. It is plumbing between adtech systems rather than a consumer-facing service, which is why it appears on huge numbers of sites while having no website a normal person would recognise.

What is criteo.com?

criteo.com (and criteo.net) is Criteo, the retargeting company — the reason products you viewed follow you across the web. Its tags collect product-view and purchase events on retail sites and use them to bid on ad impressions elsewhere. On an e-commerce site, a Criteo tag is usually a deliberate marketing integration; check that it is only on the pages the marketing team intended.

What is quantserve.com?

quantserve.com is Quantcast, which operates both an audience-measurement panel and a programmatic advertising business. Its pixel measures site audiences; publishers historically added it for the free measurement product. It is also the domain behind Quantcast Choice, a consent-management platform.

What is scorecardresearch.com?

scorecardresearch.com belongs to Comscore, the audience measurement company. Its beacons measure site and campaign reach for the panels that produce Comscore's industry ratings. It is one of the oldest and most widespread measurement pixels on the web — practically legacy infrastructure at this point.

What is rlcdn.com?

rlcdn.com is LiveRamp's identity-resolution domain (a legacy of Rapleaf, the company LiveRamp grew from). It connects identifiers across sites and devices so advertisers can match audiences — which makes it one of the more privacy-significant domains on this list, and one your consent management should definitely govern.

What is crwdcntrl.net?

crwdcntrl.net is Lotame, a data management platform (DMP). Its tags collect audience segment data — interests, behaviors, demographics inferences — for targeting and data-selling. Like rlcdn.com, it is squarely in the category regulators care about: cross-site profiling infrastructure.

What is btloader.com?

btloader.com is Blockthrough, an adblock-recovery service: it detects ad blockers and serves "acceptable ads" to users running them. Publishers add it to recover ad revenue. If you did not, one of your ad partners did.

What is bat.bing.com?

bat.bing.com hosts Microsoft Advertising's UET (Universal Event Tracking) tag — the Bing Ads equivalent of the Google Ads conversion pixel. It records conversions and builds remarketing audiences for Microsoft's ad network. Expected wherever a marketing team runs Microsoft Ads.

What is gigya.com?

gigya.com is SAP Customer Data Cloud, formerly Gigya — customer identity and access management (registration, social login, profiles). Unlike most of this list it is not adtech: if it is on your site, it is usually a deliberate CIAM integration handling login flows, which makes it a high-trust dependency worth watching closely.

When an unknown domain is a real problem

Everything above is legitimate infrastructure. The uncomfortable part: a skimmer domain looks exactly the same in your network tab. Magecart operators register domains that imitate this ecosystem — a plausible-sounding adtech name, loaded by a script your page trusts — precisely because teams have learned to shrug at unfamiliar hostnames.

Three questions separate noise from findings:

  1. Can you attribute it? Every domain above maps to a real vendor with documentation. A domain with no company behind it, registered recently, is a finding.
  2. Does it belong on this page? An ad exchange on your article pages is normal. Any of these — or anything unattributed — executing on your checkout or login page deserves an answer. This is exactly what PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 formalise for payment pages: an inventory of every script, with justification, and tamper detection.
  3. Did it change? The domain being known is not enough — the Polyfill.io incident showed a trusted, allowlisted domain turning malicious after an ownership change. A Content Security Policy controls where scripts load from, but not what a permitted script does after it loads.

Manually keeping this inventory is not realistic — the chain changes without any deploy on your side. That is the job of client-side script monitoring: watching real sessions, inventorying every script that executes, and alerting when a new domain appears or a known script's payload changes.

The takeaway

The network tab is not noise; it is the only honest inventory of who runs code on your pages. Most of what you find there is the ordinary machinery of advertising and analytics — Google, Microsoft, Comscore, the exchanges. Knowing what each domain is turns the list from anxiety into an audit. And for the pages where money and credentials change hands, that audit should be continuous, not a one-off DevTools session.

Simon Wijckmans
Founder & CEO

Founder and CEO of cside. Previously a product manager on Cloudflare Page Shield (now Cloudflare Client-Side Security). Co-chair of the W3C Anti-Fraud Community Group and a Forbes 30 Under 30 honoree. Building accessible security against client-side attacks, web security is not an enterprise-only problem.

FAQ

Frequently Asked Questions

Start with the request itself: what page loaded it, what resource type it is (script, pixel, iframe), and what initiated it — DevTools' initiator chain shows which script created the request. Then check the domain against known tracker lists and vendor documentation. Most opaque domains belong to a small set of adtech and analytics vendors, and the parent company usually documents its hostnames. If you cannot attribute a domain to a vendor you deliberately added, treat it as a finding to investigate, not background noise.

The domains in this guide are operated by legitimate companies — Google, Microsoft, Comscore, Magnite, Criteo — and are not malware. The risk is different: each one is a third party executing in your users' sessions, collecting data under your name, and each is a supply-chain dependency. Legitimate scripts get compromised, misconfigured, or quietly change behavior. The question is not whether the vendor is real, but whether you know the script is there, what it does, and whether it should be on that particular page.

Because scripts load scripts. You add one tag manager or one ad partner, and it loads its own dependencies, which load theirs. A single ad slot can trigger requests to a dozen exchanges via header bidding. This fourth-party chain is invisible in your source code — it exists only in the browser at runtime, which is why the network tab shows domains your repository has never heard of.

You need visibility at the browser layer, because the chain of script-loads-script only exists there. cside's script monitoring watches real sessions: it inventories every script that executes, fetches and analyses third-party scripts server-side, and alerts on new domains, changed payloads, and unexpected data flows. That inventory is also what PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 ask payment pages to have.

Monitor and Secure Your Third-Party Scripts

Gain full visibility and control over every script delivered to your users to enhance site security and performance.

Start free, or try Business with a 14-day trial.

cside dashboard interface showing script monitoring and security analytics
Related Articles
Book a demo

Want to walk through this with an engineer?

Thirty minutes, on your own site. Not a slide deck.

We'll show you:

Which third-party scripts are running on your site right now
Where you stand on PCI DSS 6.4.3 and 11.6.1
How much of your traffic is bots and AI agents

Rather just send a question?

Finding open slots…

Real humans only. We'd know.

Having trouble booking? Open scheduler in a new tab

What are you trying to solve?

Tell us in a line and we'll come back with something useful, not a generic pitch.

We usually help with:

Seeing which third-party scripts run on your site
PCI DSS 6.4.3 and 11.6.1 evidence
Bots, AI agents and account takeover

Prefer to just book a time? Pick a slot instead