Website Cookie Scanning

Prev Next

In Short

BigID’s Website Cookie Scanning helps you discover and manage all tracking technologies used on your website, including cookies, beacons, and scripts. It scans your entire site and subdomains, classifies most trackers automatically, and provides tools to review, edit, and export the data.

Access: Cookies & Trackers > Scanner

How It Works

After adding a domain, BigID performs a multi-layered scan that detects:

  • Cookies (first- and third-party)

  • Beacons

  • Scripts

Most tracker are automatically classified (e.g., Necessary, Marketing, Statistics) and enriched with metadata like vendor, expiration, and detection path.

For each tracker discovered, BigID classifies and enriches most of them with key metadata, including:

  • Tracker type and ID

  • Hostname

  • Vendor (when identifiable)

  • Classification (e.g., Necessary, Marketing, Statistics, Preference)

  • Expiration period

  • Path

Intelligent Crawling

BigID’s scanner emulates real browsing behavior by:

  1. Starting from the root domain (e.g., bigid.com)

  2. Navigating through all internal subpaths and subdomains

  3. Recursively following internal links to discover deeper pages

  4. Restricting the scan to only links within the same domain. External links are not included in the scan.

Example

When scanning bigid.com, the following will be processed:

  • bigid.com/discovery-foundation (subpath) – scanned

  • home.bigid.com/demo (subdomain) – scanned

  • iapp.com (external) – ignored

Scanning Behavior & Timeline

Scans typically take 5 minutes to 2 hours, depending on site complexity, number of links, and amount of embedded content. Most trackers are classified automatically using BigID’s tracker database.

Tips for Successful Scans:

  • Domain Format: Enter your domain without https:// or www.

    • Correct: bigid.com

    • Incorrect: https://bigid.com, www.bigid.com

  • Private or Restricted Sites: If your site is behind a firewall or access-restricted, whitelist BigID scanner IPs to enable successful scanning.

Cookies & Trackers Management

After a scan is complete, BigID provides a comprehensive dashboard and management tools for reviewing and organizing your trackers.

The visual dashboard includes:

  • Total trackers by type (Cookies, Beacons, Scripts)

  • Total trackers by classification (Necessary, Marketing, etc.)

  • Filters and search options for deeper exploration.

Classify Cookies & Trackers

BigID automatically classifies most trackers during the scan. For any remaining unclassified trackers, you can complete the classification in one step. To do this, select multiple trackers and choose the “Classify” option to assign a classification in bulk. You can also classify individual trackers by clicking the edit option next to each tracker.

Edit Cookies and Trackers Details

You can edit or complete the information of any cookie or tracker at any time. To do this, click the edit (pencil) icon next to the tracker you want to update.

The following fields can be modified:

  • Classification category

  • Vendor name

  • Expiration duration

  • Description in each language

This helps ensure that your consent banners and compliance reports display accurate and complete information.

Re-scan the Site

To keep your website compliant and up to date, performing regular scans is essential. With BigID, you can:

  • Manually initiate a new scan at any time by clicking the spinning refresh icon.

  • Enable Automated Monthly Scans from the three-dot menu at the top of the page.

These options ensure that any changes to your site’s trackers are continuously monitored and reflected in your dashboard.

Export Cookie Data

You can export the entire tracker dataset as a CSV file. The file includes:

  • Tracker ID

  • Hostname

  • Classification

  • Vendor

  • Expiration

  • Path (URL where it was first found)

Check Cookie Paths

Each tracker record includes the exact path or page where it was first detected (for example: bigid.com/discovery-foundation). This helps pinpoint where a specific script or cookie is injected into your site.

You can view this information by:

  • Opening the tracker details and clicking Edit, or

  • Enabling the Path column in the dashboard to see all tracker paths in one place.

Add a Cookie or Tracker Manually

At the top of the Scanner page, click + Add Tracker to add a new tracker.

  • ID: Enter a meaningful ID for the tracker so you can identify it easily in the table.

  • Hostname: Enter the hostname of the tracker. For example, https://example.com

  • Description: Describe the tracker and its purpose. English is selected by default, but you can change the language of the tracker description to any of a number of supported languages via the dropdown.

  • In the Details section, select a Clasification for the tracker, if Opt out is selected for the US, the Service that will host the tracker, and the number of hours before the tracker expires.

  • Select Wildcard match to find cookies that might even partially contain the tracker’s ID.

  • Select whether the tracker is a Cookie, Beacon, or Script.

Whitelist IPs for Cookie Scanning on Private or Firewalled Sites

If your website is not publicly accessible, such as being behind a firewall or access-restricted network, you must whitelist specific IP addresses to enable BigID Website Cookie Scanning. Only add the IPs for the region corresponding to your environment.

Production – United States (bigidcmp.cloud)

Whitelist the following IP addresses:

  • 52.54.216.172

  • 52.86.109.206

  • 107.20.227.117

Production – Australia (au.bigidcmp.cloud)

Whitelist the following IP addresses:

  • 16.176.80.89

  • 16.176.66.93

  • 13.55.100.16

Production – Indonesia (in.bigidcmp.cloud)

Whitelist the following IP addresses:

  • 16.78.116.180

  • 108.137.49.11

  • 16.78.118.35

Note: This step is only required if your site cannot be reached publicly. If your website is internet-facing and unrestricted, no action is needed.