The gtmspy scanner

gtmspy audits an online store's tracking setup (analytics and ad tags, consent banner behaviour) when someone requests an audit of that store.

What a visit does

How to recognise it

Requests to the audited store are signed with Web Bot Auth (Signature-Agent: "https://bot.gtmspy.io", tag web-bot-auth). Our public key is at /.well-known/http-message-signatures-directory. The user agent is Chrome's own, followed by gtmspy/1.0.

We never fake a browser fingerprint or user agent, use stealth tools, solve CAPTCHAs or rotate IP addresses.

Opt out or ask a question

Contact bot@gtmspy.io. We add opted-out stores to a list that is never scanned again.