Skip to main content

Keep our runs out of your numbers

The ConsentMark Monitor loads your pages every night from one fixed IP address, with a real browser's user agent, so the evidence is what a visitor sees. Filter the address once and our visits stay out of your reports.

What we are

IP address
52.211.111.173
Header
X-ConsentMark-Monitor: 1, sent only to your own site's hosts, for your WAF or CDN allowlist only.

We click nothing, fill in nothing and buy nothing, so no interaction-triggered event fires. Page-load events do, and so does a conversion counted on a URL rule, such as a key event on a confirmation page. Filter the IP, and keep confirmation pages off your watched list.

Where to put it

GA4
Admin > Data streams > your web stream > Configure tag settings > Define internal traffic: add the IP. Then set the Internal traffic data filter to Active. A filter left in Testing changes nothing, and no filter applies to data already collected. Under server-side Google Tag Manager the rule matches only if your server container forwards the visitor's IP to GA4.
Google Ads
Campaign settings > IP exclusions keeps us out of ad serving. A visit with no ad click earns no attributed conversion anyway.
Your WAF or CDN
Allowlist the IP so a rate limit or bot rule never blocks a night. If your WAF can match on both, pair it with the header X-ConsentMark-Monitor: 1. The header on its own proves nothing, because anyone can send it.
Meta and others
No IP filter exists. Only page-load events land from us. A custom conversion defined on a URL rule would count, which is why the Monitor flags a watched page the night it fires a conversion-class request.

Do not key any tag, trigger or container on our header or our IP. A container that treats us differently from a visitor blanks the evidence you are paying for.

Copy a change request

Plain text for a change ticket covering GA4, Google Ads and your WAF, with the IP filled in. It is drafted for your team to apply. We change nothing in your accounts.

Change request: keep the ConsentMark Monitor out of our analytics and let it through our WAF

Why: ConsentMark loads our pages every night from one fixed IP address, 52.211.111.173, with a real browser, to record which tags fire under each consent state. It clicks nothing, fills in nothing and buys nothing. Its page views are not visitors, and our WAF should not block it.

1. Google Analytics 4
- Admin > Data streams > (our web stream) > Configure tag settings > Define internal traffic: add a rule with traffic_type "internal" where the IP address equals 52.211.111.173.
- Admin > Data filters > Internal traffic: set the filter to Active. A filter left in Testing changes nothing.
- The filter does not apply to data already collected. If we tag through server-side Google Tag Manager, confirm the server container forwards the visitor's IP to GA4, or the rule will not match.

2. Google Ads
- Campaign settings > IP exclusions: add 52.211.111.173 to each campaign. A visit with no ad click earns no attributed conversion anyway, so this keeps the Monitor out of ad serving.

3. WAF or CDN
- Allowlist 52.211.111.173 so rate limiting and bot rules never block the nightly run.
- If the WAF can match on both, pair the IP with the request header X-ConsentMark-Monitor: 1. The header on its own proves nothing, because anyone can send it.

Do not change any tag, trigger or GTM container for this traffic. The Monitor has to see the site exactly as a visitor does.