This is the companion reference to Why Web Tracking Survives, which covers the structural forces that protect these techniques. For the legal and regulatory landscape, see The 2025-2026 Privacy Enforcement Landscape.


This guide covers every major web tracking technique in active use as of Q2 2026. It organizes them by category, explains the protocol-level mechanism for each, describes the current state of browser defenses, and gives you one concrete action to take this week. The arms race summary table at the top of the technical layer serves as a navigation roadmap. Start there to identify which techniques are most relevant to your environment, then jump to the technique sections for depth.

The guide addresses three practitioner questions:

  • How does this technique actually work at the protocol level?
  • What defenses exist, and what do they miss?
  • What should I check or do right now?

The audience is practitioners who deploy, audit, or defend against tracking infrastructure: security engineers, privacy engineers, and infrastructure engineers. CISOs and engineering leaders will find the arms race table and Monday morning actions sufficient for decision-making without reading the full technical layer.

The guide covers twelve techniques across three categories. Trust-relationship techniques exploit browser primitives that cannot be removed without breaking legitimate web functionality: first-party cookies, URL parameter tracking, pixel tracking, ETags, and HSTS. Modern stack techniques operate on surfaces outside browser visibility: browser fingerprinting, CNAME cloaking, server-side tracking, favicon cache tracking, cross-device tracking, and session replay. The emerging category covers WebGPU fingerprinting, which has shipped in all major browsers as of 2026 but has not yet achieved wide advertising deployment.

Three techniques deserve the most attention because they represent novel attack surfaces or enforcement gaps. CNAME cloaking creates a security risk beyond tracking: authentication cookies transmit to third-party infrastructure. Server-side tracking has a structural consent propagation gap that most current architectures do not address. WebGPU fingerprinting achieves entropy levels and stability that render existing browser defenses ineffective.

For legal exposure analysis on any technique, see The 2025-2026 Privacy Enforcement Landscape. This guide does not repeat that analysis per-technique - one sentence at the end of each section points to relevant regulatory categories.

This guide does not cover the structural forces that make tracking persistent across browser generations - that argument lives in Why Web Tracking Survives. It does not cover the Privacy Sandbox, AI behavioral profiling, or the post-cookie identity infrastructure landscape. Those topics appear in the companion pieces.

The detection and audit toolkit section at the end covers what standard tools catch, what they miss, and a baseline open-source kit for auditing your own properties.